Skip to main content
Connic

Separate development and production
directly in Connic.

Give each environment its own variables, connections, and optional budget limits. Connect development, staging, and production to different Git branches to deploy the right agents and code versions in each.

Read the environments docs

Environment variables

production
KeyValue
  • DATABASE_URLpostgres://••••@db.connic.co/prod
  • STRIPE_SECRET_KEYsk_live_••••••••••••••••••
  • OPENAI_API_KEYsk-••••••••••••••••••••••
  • SENTRY_DSNhttps://••••@o123.sentry.io/4501
  • AWS_S3_BUCKETconnic-prod-uploads
  • WEBHOOK_SIGNING_SECRETwhsec_••••••••••••••••••

Develop new agents independently of production

Use different branches to test new agents and changes in a separate environment. Each environment has its own code version, variables, connections, and optional budget limits.

invoice-processor
staging
DATABASE_URLpostgres://••••@db.staging.connic.co/db
STRIPE_SECRET_KEYsk_test_•••••••••••••••
OPENAI_API_KEYsk-•••••••••••••••
$5 / day budget limit
invoice-processor
production
DATABASE_URLpostgres://••••@db.connic.co/prod
STRIPE_SECRET_KEYsk_live_•••••••••••••••
OPENAI_API_KEYsk-•••••••••••••••
$500 / day budget limit

Protect sensitive values in the dashboard and logs

Mark confidential variables as sensitive. Connic hides their values in the dashboard after creation and masks them in logs. At deployment, Connic provides the agent with its environment’s variables.

Stored encrypted

Variables are stored encrypted and only injected into agent containers at deploy time.

Masked after creation

A variable marked as Sensitive has its value masked in the dashboard (shown as ••••••••) once saved.

Masked in logs

Sensitive values are masked in logs. Changes to variables require a redeployment to take effect. Details are available in the variables docs.

agents/research-agent.yaml (snippet)
mcp_servers:
  - name: research-hub
    url: https://mcp.example.com/research
    headers:
      Authorization: "Bearer ${RESEARCH_TOKEN}"
    tools:
      - search_papers
      - fetch_abstract

In agent YAML, variables use ${VAR_NAME} wherever the schema accepts a string: MCP server headers, custom LLM provider URLs, and similar config fields. Python tools and middleware read them via os.environ. Values resolve at deploy time to the bindings of the active environment.

Release changes through your Git workflow

Connect each environment to the appropriate branch. When you push changes to it, Connic starts the deployment. Check new versions in staging first, then release them through your production branch.

f3a92c1hot-reload
by connic dev
just now
8d4b1e0deployed
by push to develop
12 min ago
2c7e9a6deployed
by merge to main
yesterday

Manage more than environment variables

Compare how Connic and other approaches support environment isolation, sensitive data protection, and deployments.

Manage more than environment variables
FeatureConnic.env filesHashiCorp VaultDoppler
Per-environment scopingIncludedPartialIncludedIncluded
Stored encryptedIncludedNot includedIncludedIncluded
Sensitive values masked in logsIncludedNot includedIncludedIncluded
Project audit logIncludedNot includedIncludedPartial
Git branch → environment mappingIncludedNot includedNot includedNot included
Wired to connectorsIncludedNot includedNot includedNot included
Wired to agent specsIncludedNot includedNot includedNot included
Per-environment budget limitsIncludedNot includedNot includedNot included
No extra service to operateIncludedIncludedNot includedNot included

Frequently Asked Questions

Basic includes one environment. Developer includes three, Pro includes five, and Enterprise limits are set in the contract. Support can help when a project needs more than its tier includes.

Yes. Environment names are user-defined (Production, Staging, QA, or anything else). Each gets its own variables, its own connector wiring, and can carry its own budget limits.

The variable value is updated in the dashboard before a redeployment. Variable changes only take effect on the next deployment; the running one keeps using the previous values until then.

When a variable is marked as Sensitive, its value is masked in the dashboard (shown as ••••••••) and in logs. Variables are stored encrypted and only injected into agent containers at deploy time.

Yes. Project changes (variable edits, deployments, approval decisions) are recorded in the project audit log, accessible from Project Settings → Audit Log.

Yes. Connect production to live Stripe, Kafka, and Postgres systems and staging to their sandboxes. Set variables and connections per environment. Different Git branches also let environments run different agents and code versions.