# Environment Variable

URL: https://softwaredictionary.org/terms/environment-variable
Category: DevOps & Cloud
Last updated: 2026-09-30
In Turkish: Ortam Değişkeni

In short: An environment variable is a named value set outside a program, by the operating system or runtime, that the program reads to configure its behavior.

## What is an environment variable?

An environment variable is a key-value pair, such as `PORT=3000` or `NODE_ENV=production`, that belongs to the environment a program runs in rather than to the program's code. Every process receives a copy of its parent's environment variables when it starts, and the program can read them to decide how to behave. Operating systems also use them for their own settings, such as `PATH`, which lists the folders where the shell looks for commands.

Environment variables are the standard way to give the same code different settings in different places, such as a local database on a laptop and a production database in the cloud. Keeping configuration out of the codebase this way is a core idea of the twelve-factor app methodology. In Node.js you read them with `process.env.NAME`, in Python with `os.environ`, and in a shell with `$NAME`, and containers, CI/CD pipelines, and hosting platforms all let you set them per environment.

Think of the settings in a rental car: the car (your code) is the same for everyone, but each driver adjusts the seat and mirrors (the variables) before driving off. During local development, many projects keep variables in a `.env` file that a library or the runtime loads at startup; Node.js, for example, can read one with the `--env-file` flag.

A common mistake is treating environment variables as automatically secret. They are convenient for secrets like API keys, but a `.env` file should never be committed to Git; add it to `.gitignore` and commit a `.env.example` file with placeholder values instead. Also, in frontend frameworks, variables exposed to the browser, usually marked with a prefix such as `NEXT_PUBLIC_` or `VITE_`, are embedded in the JavaScript bundle and visible to anyone, so they must never contain secrets.

## Key takeaways

- Environment variables are key-value settings provided by the environment, not the code.
- They let the same code run with different configuration in each environment.
- Child processes inherit a copy of their parent's environment variables.
- Never commit `.env` files that contain secrets to version control.
- Values exposed to frontend code are public, so keep secrets on the server.

## Example: Setting and reading environment variables in a shell

```bash
# Set a variable for the current shell session, then read it
export API_URL="https://api.example.com"
echo "$API_URL"

# Set a variable for a single command only
PORT=8080 node server.js

# List all environment variables, or show just your PATH
env
echo "$PATH"

# Load variables from a .env file into a Node.js app (Node.js 20.6 and later)
node --env-file=.env server.js
```

## Frequently asked questions

**What is a .env file?**

A `.env` file is a plain text file of `KEY=value` lines that stores environment variables for local development. Tools and runtimes load it at startup, and it should be listed in `.gitignore` because it often contains secrets.

**Are environment variables secure for storing secrets?**

They are safer than hard-coding secrets in source code, but not fully secure, because any code in the process, and sometimes crash reports or debugging tools, can read them. For production, many teams use a dedicated secrets manager that injects values at runtime and supports rotation and access control.

**Why is my environment variable undefined?**

Common causes are a typo in the name, setting it in a different terminal session, forgetting to restart the app after a change, or, in frontend frameworks, missing the required public prefix. Variables are read when a process starts, so changes do not affect programs that are already running.

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
