Separate development and production
directly in Connic.
Give each environment its own variables, connections, and optional budget limits. Connect development, staging, and production to different Git branches to deploy the right agents and code versions in each.
Read the environments docsEnvironment variables
- DATABASE_URLpostgres://••••@db.connic.co/prod
- STRIPE_SECRET_KEYsk_live_••••••••••••••••••
- OPENAI_API_KEYsk-••••••••••••••••••••••
- SENTRY_DSNhttps://••••@o123.sentry.io/4501
- AWS_S3_BUCKETconnic-prod-uploads
- WEBHOOK_SIGNING_SECRETwhsec_••••••••••••••••••
Develop new agents independently of production
Use different branches to test new agents and changes in a separate environment. Each environment has its own code version, variables, connections, and optional budget limits.
Protect sensitive values in the dashboard and logs
Mark confidential variables as sensitive. Connic hides their values in the dashboard after creation and masks them in logs. At deployment, Connic provides the agent with its environment’s variables.
Variables are stored encrypted and only injected into agent containers at deploy time.
A variable marked as Sensitive has its value masked in the dashboard (shown as ••••••••) once saved.
Sensitive values are masked in logs. Changes to variables require a redeployment to take effect. Details are available in the variables docs.
mcp_servers:
- name: research-hub
url: https://mcp.example.com/research
headers:
Authorization: "Bearer ${RESEARCH_TOKEN}"
tools:
- search_papers
- fetch_abstractIn agent YAML, variables use ${VAR_NAME} wherever the schema accepts a string: MCP server headers, custom LLM provider URLs, and similar config fields. Python tools and middleware read them via os.environ. Values resolve at deploy time to the bindings of the active environment.
Release changes through your Git workflow
Connect each environment to the appropriate branch. When you push changes to it, Connic starts the deployment. Check new versions in staging first, then release them through your production branch.
Manage more than environment variables
Compare how Connic and other approaches support environment isolation, sensitive data protection, and deployments.
| Feature | Connic | .env files | HashiCorp Vault | Doppler |
|---|---|---|---|---|
| Per-environment scoping | Included | Partial | Included | Included |
| Stored encrypted | Included | Not included | Included | Included |
| Sensitive values masked in logs | Included | Not included | Included | Included |
| Project audit log | Included | Not included | Included | Partial |
| Git branch → environment mapping | Included | Not included | Not included | Not included |
| Wired to connectors | Included | Not included | Not included | Not included |
| Wired to agent specs | Included | Not included | Not included | Not included |
| Per-environment budget limits | Included | Not included | Not included | Not included |
| No extra service to operate | Included | Included | Not included | Not included |