Docs
Environment variables
Tofu keeps each variable’s name, scopes and whether it is a secret. A secret’s value goes straight to the hosting provider’s write-only store, and nothing in Tofu — the dashboard, your agent or its database — can read it back.
Agent tools
listEnvmanageEnvironment
Where a value lives
| Kind | What Tofu keeps |
|---|---|
| Secret | The name, its scopes and a masked preview (the last four characters; a value of four or fewer is masked entirely). The value is sent to the hosting provider as sensitive and never comes back. |
| Not a secret | The name, its scopes and the value, which the dashboard shows. |
| Managed | Written by Tofu — the database connection, for example — and read-only: see Database. |
Every variable carries one or more scopes — production, preview and development — and a new one gets production and preview unless you choose otherwise.
Adding variables
In the dashboard’s Environment page for the app.
Before the first deployment
Variables that are not secrets can be saved already; a secret needs the app's hosting project, which the first deployment creates.
Before every build
Deployments receive each variable in its scopes before the build starts, so a build step can read them.
On the next deployment
A change applies to deployments that follow it. Saving does not redeploy the app.
A secret stays a secret: it cannot be turned into a plain variable later. Delete it and add it again if it was never meant to be one.
Importing a .env file
Pasting a .env file treats every value as a secret, because a variable's name cannot prove its value holds no credential — a DATABASE_URL with a password in it, for example. To store public configuration before deploying, add it on its own with Secret unchecked.
Lines that are invalid, that name a reserved key or that name a managed variable are skipped. An import saves one variable at a time, so if something fails partway, the ones before it are saved and the page says that some may have been.
Your agent and your secrets
listEnv gives your agent the names, scopes and the secret flag — never a value, not even a non-secret one. When the app needs a value, manageEnvironment hands you the dashboard address for that exact app, and you type it there.
That is deliberate: a secret's value is never returned by Tofu's API or stored in its database, so it is never in a chat, a tool result or a transcript. For the same reason no tool deletes a variable — an agent that could remove configuration it cannot restore could break an app it cannot fix.
Limits
What Tofu does not do with values
Show a secret again. Neither the dashboard nor your agent can read a secret’s value back; to change it, save a new one.
Set a reserved key. Keys starting with
VERCEL_are reserved, and Tofu refuses them.Save two places at once. The provider and Tofu’s records are not one transaction: if a save fails after the provider accepted it, Tofu reports the failure, and saving again reconciles it.
Take values from your agent. No tool writes a value; values are typed in the dashboard.
The ship-it layer for vibe-coded apps. Your agent wrote it — Tofu ships it.
Works in all coding agents
© 2026 Tofu
trytofu.ai