# Environment variables

An environment variable is a key-value pair stored outside your function code. It holds a configuration value or a secret, such as an API key, a database credential, or an access token. The value never enters the codebase or a version control system. A [function](/en/documentation/platform/functions/) reads the value by its key at run time, so a new value takes no edit to the code.

---

## Variable fields

An environment variable carries three fields:

| Field    | Type    | Description                                    |
| -------- | ------- | ---------------------------------------------- |
| `key`    | string  | Name the function passes to `Azion.env.get()`. |
| `value`  | string  | Value returned for that key.                   |
| `secret` | boolean | Whether the value is confidential.             |

Azion assigns each variable an ID when it is created. The `--variable-id` flag of Azion CLI names it on `azion describe variables`, `azion update variables`, and `azion delete variables`.

Environment variables are stored on the account, and an account holds a maximum of 100 of them. The 32 KB cap is measured per function rather than per account: it bounds the total size of all environment variables for a single function. For every Functions limit, refer to [Limits](/en/documentation/platform/functions/limits/).

---

## Access from function code

A function reads a variable with the `Azion.env.get()` interface, which takes the key and returns the value:

```javascript
const apiToken = Azion.env.get('API_SERVICE_TOKEN');
```

The call returns a string. A key that does not exist returns `undefined` rather than an error, and the function continues with that undefined value. A handler written in the ES Modules pattern also receives `env`, the object that carries the environment variables and the bindings available to the function.

For the parameters, the return value, and a longer example, refer to [Environment Variables interface](/en/documentation/devtools/runtime/api-reference/environment-variables/). Azion Runtime also supports `process.env` for Node.js compatibility, covered in [process](/en/documentation/devtools/runtime/node/process/).

---

## Management interfaces

You create, list, change, and delete environment variables through the [Azion API](https://api.azion.com/), with [Azion CLI](/en/documentation/devtools/cli/), and with the [Azion Terraform provider](/en/documentation/devtools/terraform/), where the resource is `azion_environment_variable`.

Azion CLI carries one subcommand per operation: `azion create variables`, `azion list variables`, `azion describe variables`, `azion update variables`, and `azion delete variables`. The `--key`, `--value`, and `--secret` flags set the three fields, and `--secret` defaults to `true`. The `--file` flag reads the same three fields from a JSON file instead.

```bash
azion create variables --key "Content-Type" --value "string" --secret false
```

A variable whose key contains `password`, `pwd`, `secret`, `key`, `hash`, `encrypted`, `passcode`, `auth`, or `token` is sent as a secret by default.

The `azion sync` command reads the variables in a local `.env` file and sends them to your account. The `--env` flag sets the path to that file, and the default is `.edge/.env`.

A change to a variable does not reach a function that is already running. The function is redeployed for the new value to take effect.

For the attributes `azion update variables` accepts, refer to [Variables](/en/documentation/devtools/cli/resources/variables/).

---

## Related resources

- [Environment variables API](/en/documentation/devtools/runtime/api-reference/environment-variables.md): The syntax, the parameters, and the return value of `Azion.env.get()`.
- [Function instances](/en/documentation/platform/applications/functions-instances.md): The Args an instance carries, for configuration that changes per instance.
- [Azion CLI](/en/documentation/devtools/cli.md): Every flag of the `variables` subcommands and of `azion sync`.
- [Limits](/en/documentation/platform/functions/limits.md): The 32 KB ceiling and every other Functions limit.
- [Functions](/en/documentation/platform/functions.md): What a function is and what invokes it.
