1. Reference
  2. Environment variables

Reference

Environment variables reference

Environment variables belong to an organization. Uptime checks can use them in HTTP request header values and HTTP Basic Auth usernames and passwords. They do not work in browser checks or other check fields.

Type Value visibility Use
config Readable in the dashboard and API Non-sensitive settings
secret Write-only; can be replaced but not read after saving Credentials

The type cannot change after creation. An organization can have up to 1,000 variables. Names are case-sensitive and unique within the organization. They match [A-Z_][A-Z0-9_]{0,63}. Values can be empty. Each value can contain up to 8 KiB of UTF-8 text.

HTTP request reference syntax

Saved value Result
Header: Bearer {{API_TOKEN}} Inserts the current value of API_TOKEN after Bearer .
Basic Auth password: {{API_TOKEN}} Uses the current value as the HTTP Basic Auth password.
Username: user-{{ACCOUNT}} Inserts the current value after user-.
{{{{API_TOKEN}}}} Sends the literal text {{API_TOKEN}}.

A header or Basic Auth credential can contain more than one reference. Expansion happens once: a variable value that contains {{OTHER}} is not expanded again. A check cannot use a name that does not exist. Header names, URLs, bodies, assertions, and browser checks do not support references.

Template limit Maximum
Distinct referenced variables across headers and Basic Auth credentials 32
Expanded value per header or Basic Auth field 8,192 UTF-8 bytes
Total rendered headers (names and expanded values) 32,768 UTF-8 bytes

These limits are separate from the 8 KiB variable-value limit. For example, an 8,192-byte API_TOKEN value fits the variable limit but exceeds the expanded header limit in Bearer {{API_TOKEN}}. Expanded header values and Basic Auth credentials cannot contain line breaks.

A variable in use by a saved check cannot be deleted, even if the check is paused. Renaming a variable updates references in saved checks. It does not update Terraform files. A run dispatched before a value change can still use the earlier value.

Secret values do not appear in API responses. OnlineOrNot removes exact secret values from check results, but encoded or changed values can still appear. An editor of uptime checks can send a secret to an endpoint they control. Do not use config for credentials.

The environment variables API supports list and create at /v1/env. It supports read, update, and delete at /v1/env/{environment_variable_id}. API tokens need ENVIRONMENT_VARIABLES:READ to list or read. They need ENVIRONMENT_VARIABLES:EDIT to create, update, or delete. The uptime checks API accepts references in header values, auth_username, and auth_password. Terraform supports references in the headers map of onlineornot_uptime_check. Secret variables can be managed with onlineornot_environment_variable; config variables must be created through the dashboard or API. Terraform stores the reference in the header template, not the secret value.

To set up a check, see Use environment variables in uptime checks.