# Azion CLI variables

The Azion CLI `variables` commands create, list, describe, update, and delete the [environment variables](/en/documentation/platform/functions/environment-variables/) of your account, the key-value pairs and secrets that a function reads by key at run time. Each variable has a UUID, which the `--variable-id` flag takes. The options every command accepts, such as `--format`, `--out`, and `-y`, are on [Global options](/en/documentation/devtools/cli/globals/).

---

## Create

`azion create variables` creates an environment variable or a secret for your functions to use:

```bash
azion create variables [flags]
```

| Flag       | Short | Type   | Default | Description                                                                                              |
| ---------- | ----- | ------ | ------- | -------------------------------------------------------------------------------------------------------- |
| `--file`   | —     | string | —       | Path to a JSON file with the attributes of the variable. Use `-` to read the JSON from standard input.   |
| `--key`    | —     | string | —       | Key of the variable. A function reads the value by this key.                                             |
| `--secret` | —     | string | —       | Marks the value as confidential (`true`) or not (`false`). The CLI prints a confidential value as empty. |
| `--value`  | —     | string | —       | **Required** unless `--file` is set. Value of the variable. Without it, the command asks for the value.  |

This command creates a variable with the key `MY_VARIABLE` and a value that is not confidential:

```bash
azion create variables --key MY_VARIABLE --value plain-value --secret false
```

The command prints the UUID of the variable:

```text
Created variable with UUID 00000000-0000-0000-0000-000000000005
```

---

## List

`azion list variables` lists the environment variables and secrets of your account:

```bash
azion list variables [flags]
```

| Flag        | Short | Type | Default | Description                                                                                                                         |
| ----------- | ----- | ---- | ------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `--details` | —     | —    | —       | Adds the `SECRET` and `LAST EDITOR` columns to the `ID`, `KEY`, and `VALUE` columns.                                                |
| `--dump`    | —     | —    | —       | Writes the variables to a `.env` file in the current directory, one `KEY=value` line per variable. Secret values are written empty. |

This command lists the variables of the account:

```bash
azion list variables
```

The command prints one row per variable. The `VALUE` column of a secret is empty:

```text
ID                                    KEY                 VALUE
00000000-0000-0000-0000-000000000005  MY_VARIABLE         plain-value
00000000-0000-0000-0000-000000000006  MY_SECRET
```

With `--dump`, the command prints `Variables file (.env) dumped successfully` and writes this `.env` file for the same two variables:

```text
MY_VARIABLE=plain-value
MY_SECRET=
```

---

## Describe

`azion describe variables` prints the attributes of one variable:

```bash
azion describe variables [flags]
```

| Flag            | Short | Type   | Default | Description                                     |
| --------------- | ----- | ------ | ------- | ----------------------------------------------- |
| `--variable-id` | —     | string | —       | **Required**. UUID of the variable to describe. |

This command describes the variable with UUID `00000000-0000-0000-0000-000000000005`:

```bash
azion describe variables --variable-id 00000000-0000-0000-0000-000000000005
```

The command prints the key, the value, and the history of the variable:

```text
Uuid:          00000000-0000-0000-0000-000000000005
Key:           MY_VARIABLE
Value:         plain-value
Secret:        false
Last Editor:   you@example.com
Create At:     "2026-01-01T12:00:00.139877Z"
Update At:     "2026-01-01T12:00:00.139898Z"
```

With `--format json`, the command prints the full object: `created_at`, `key`, `last_editor`, `secret`, `updated_at`, `uuid`, and `value`. For a secret, `value` is an empty string (`""`). With `--out var-describe.json`, the command writes that JSON object to the file and prints `File successfully written to: var-describe.json`.

A UUID that does not exist, or a numeric ID, fails with this error:

```text
Error: Failed to describe the variable: The given ID or API's endpoint doesn't exist or isn't available. Check that the identifying information is correct. Check your settings and try again. If the error persists, contact Azion support.
```

---

## Update

`azion update variables` changes the key, the value, or the confidentiality of a variable:

```bash
azion update variables [flags]
```

| Flag            | Short | Type   | Default | Description                                                                                                                              |
| --------------- | ----- | ------ | ------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
| `--file`        | —     | string | —       | Path to a JSON file with the attributes to change. Use `-` to read the JSON from standard input.                                         |
| `--key`         | —     | string | —       | **Required** unless `--file` is set. Key of the variable. Without it, the command asks for the key, even when you change only the value. |
| `--secret`      | —     | string | —       | Marks the value as confidential (`true`) or not (`false`).                                                                               |
| `--value`       | —     | string | —       | Value to set on the variable.                                                                                                            |
| `--variable-id` | —     | string | `"0"`   | **Required** unless the `--file` JSON carries `"uuid"`. UUID of the variable to update.                                                  |

This command sets the value of the variable with UUID `00000000-0000-0000-0000-000000000005` to `updated-value` and keeps its key:

```bash
azion update variables --variable-id 00000000-0000-0000-0000-000000000005 --key MY_VARIABLE --value updated-value --secret false
```

The command prints the UUID of the updated variable:

```text
Updated variable with UUID 00000000-0000-0000-0000-000000000005
```

A describe of the variable then returns `updated-value` as its value.

---

## Delete

`azion delete variables` deletes a variable:

```bash
azion delete variables [flags]
```

| Flag            | Short | Type   | Default | Description                                   |
| --------------- | ----- | ------ | ------- | --------------------------------------------- |
| `--variable-id` | —     | string | —       | **Required**. UUID of the variable to delete. |

This command deletes the variable with UUID `00000000-0000-0000-0000-000000000005`:

```bash
azion delete variables --variable-id 00000000-0000-0000-0000-000000000005
```

The command confirms the deletion:

```text
Variable 00000000-0000-0000-0000-000000000005 was successfully deleted
```

---

## Use a JSON file

`azion create variables` and `azion update variables` read the attributes of a variable from a JSON file with `--file`.

This file creates a secret with the key `MY_SECRET`. The command reads `key`, `value`, and `secret` from it:

```json
{
  "key": "MY_SECRET",
  "value": "my-secret-value",
  "secret": true
}
```

Pass the file to the create command:

```bash
azion create variables --file var-create.json
```

The command prints the UUID of the secret:

```text
Created variable with UUID 00000000-0000-0000-0000-000000000006
```

On update, the command also reads `"uuid"` from the file, so `--variable-id` is not needed. This file changes the value of the secret with UUID `00000000-0000-0000-0000-000000000006`:

```json
{
  "uuid": "00000000-0000-0000-0000-000000000006",
  "key": "MY_SECRET",
  "value": "my-secret-value-2",
  "secret": true
}
```

Pass the file to the update command:

```bash
azion update variables --file var-update.json
```

The command prints the UUID of the updated secret:

```text
Updated variable with UUID 00000000-0000-0000-0000-000000000006
```

A describe of the secret then shows a later `updated_at` time and `"value": ""`, because the CLI does not print a confidential value back.

---

## Related resources

- [Global options](/en/documentation/devtools/cli/globals.md): The options every command accepts, such as `--format`, `--out`, and `-y`.
- [Environment variables](/en/documentation/platform/functions/environment-variables.md): What a variable holds, how a function reads it, and the limits that apply.
- [Azion CLI function](/en/documentation/devtools/cli/resources/function.md): The commands that create and manage the functions that read these variables.
