Reference
Environment variables reference
Environment variables belong to an organization. Uptime checks can use them in HTTP request header values and HTTP Basic Auth usernames and passwords. They do not work in browser checks or other check fields.
| Type | Value visibility | Use |
|---|---|---|
config |
Readable in the dashboard and API | Non-sensitive settings |
secret |
Write-only; can be replaced but not read after saving | Credentials |
The type cannot change after creation. An organization can have up to 1,000 variables. Names are case-sensitive and unique within the organization. They match [A-Z_][A-Z0-9_]{0,63}. Values can be empty. Each value can contain up to 8 KiB of UTF-8 text.
HTTP request reference syntax
| Saved value | Result |
|---|---|
Header: Bearer {{API_TOKEN}} |
Inserts the current value of API_TOKEN after Bearer . |
Basic Auth password: {{API_TOKEN}} |
Uses the current value as the HTTP Basic Auth password. |
Username: user-{{ACCOUNT}} |
Inserts the current value after user-. |
{{{{API_TOKEN}}}} |
Sends the literal text {{API_TOKEN}}. |
A header or Basic Auth credential can contain more than one reference. Expansion happens once: a variable value that contains {{OTHER}} is not expanded again. A check cannot use a name that does not exist. Header names, URLs, bodies, assertions, and browser checks do not support references.
| Template limit | Maximum |
|---|---|
| Distinct referenced variables across headers and Basic Auth credentials | 32 |
| Expanded value per header or Basic Auth field | 8,192 UTF-8 bytes |
| Total rendered headers (names and expanded values) | 32,768 UTF-8 bytes |
These limits are separate from the 8 KiB variable-value limit. For example, an 8,192-byte API_TOKEN value fits the variable limit but exceeds the expanded header limit in Bearer {{API_TOKEN}}. Expanded header values and Basic Auth credentials cannot contain line breaks.
A variable in use by a saved check cannot be deleted, even if the check is paused. Renaming a variable updates references in saved checks. It does not update Terraform files. A run dispatched before a value change can still use the earlier value.
Secret values do not appear in API responses. OnlineOrNot removes exact secret values from check results, but encoded or changed values can still appear. An editor of uptime checks can send a secret to an endpoint they control. Do not use config for credentials.
The environment variables API supports list and create at /v1/env. It supports read, update, and delete at /v1/env/{environment_variable_id}. API tokens need ENVIRONMENT_VARIABLES:READ to list or read. They need ENVIRONMENT_VARIABLES:EDIT to create, update, or delete. The uptime checks API accepts references in header values, auth_username, and auth_password. Terraform supports references in the headers map of onlineornot_uptime_check. Secret variables can be managed with onlineornot_environment_variable; config variables must be created through the dashboard or API. Terraform stores the reference in the header template, not the secret value.
To set up a check, see Use environment variables in uptime checks.