SDKs & infrastructure

Environment variables

Environment variables are named configuration values supplied to a running process, often used to keep deployment settings separate from application source code.

Also found under: Server configuration, Environment secrets

How it works

A value is not confidential merely because it came from an environment variable. Frontend frameworks can embed public-prefixed values into downloaded code. Keep server secrets out of logs, client responses and committed configuration, and use separate settings for development and production environments.

In a Pubb integration

Backend examples use PUBB_APP_ID, PUBB_APP_KEY and PUBB_APP_SECRET. Only the public app key should be exposed to clients using the framework's public configuration convention.

Set up application credentials

A practical example

A backend reads PUBB_APP_SECRET at runtime when publishing an event. The browser receives its public app key but never a public-prefixed copy of the secret.