You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys. See Permission reference for every permission.
--prunedeletes every variable you didn’t send.--prune --variables='[]'removes them all.kinddefaults towriteonly, which can never be read back. Set"kind":"recoverable"solist-environment-variablescan return the value.
Usage
Flags
string
required
App ID or slug.
string
required
Environment ID or slug.
string
required
Project ID or slug. Both forms resolve to the same project.
boolean
default:"false"
Delete every variable not present in
--variables after the upsert.string
required
JSON array of at most 50 variables, each with
key and value and optionally kind and description, for example [{"key":"TOKEN","value":"secret"}]. A key must be a POSIX shell name of at most 256 characters and may appear only once. A value is capped at 16384 UTF-8 bytes, and a description at 255 characters.Shared flags
Everyunkey api command accepts these; CLI output and shared flags describes them in full.
string
A JSON document sent as the request body instead of building it from the flags above. It is mutually exclusive with the request-building flags, and unknown fields are rejected locally. See Send a raw body.
string
Root key for the request. Falls back to
UNKEY_ROOT_KEY, then to the config file written by unkey auth login. See CLI authentication.string
default:"https://api.unkey.com"
Base URL of the API. Falls back to
UNKEY_API_BASE_URL. You don’t normally need to set it.string
default:"~/.unkey/config.toml"
Path of the TOML file that
unkey auth login writes. Falls back to UNKEY_CONFIG.string
Output format. Falls back to
UNKEY_OUTPUT. Set json to print the full response envelope (meta and data) for piping; any other value prints the request ID followed by data.Required permissions
Your root key needs one of:environment.*.set_environment_variables(any environment)environment.<environment_id>.set_environment_variables(a specific environment)
Permission denied: followed by the detail. See Root key permissions for the full catalog.
Examples
Set one variable:API endpoint
The command callsPOST /v2/environments.setEnvironmentVariables and prints its response. The request fields carry the same names as the flags in camelCase, which is the shape --body expects.
Related
Environment variables
Kinds, encryption, and how variables reach a deployment.