Purpose
Config is explicit, per environment, and never committed.
The standard
.env.exampleis committed and lists every variable with a placeholder and a one-line comment..env.localis gitignored.Browser-exposed values are prefixed
NEXT_PUBLIC_and are never secrets.Production values live only in the hosting provider (Vercel) or the secret manager (07.01) — not in chat, docs, or repos.
Validate env at startup with a schema (
zod) so a missing variable fails loudly at boot, not at 2 a.m.Feature flags are env-driven for now (
FEATURE_X=true); revisit if we exceed ~10.
Procedure — adding a variable
Add to
.env.examplewith comment. 2. Add to the env schema. 3. Add to Vercel for preview and production. 4. Note it in the PR description.
Owner: Matt · Last reviewed: 2026-09