Choose build time or runtime
Build-time values are available while the project is built. Frontend frameworks may compile public variables directly into JavaScript that visitors can download. Runtime values are supplied when the application runs. The correct choice depends on how your code reads the setting.
Naming a variable private does not keep it secret if the frontend publishes it. Review the framework’s behavior and the destination of the value. Public API base URLs and server-side access credentials have different security requirements.
Keep configuration attached to the right app
Identify the project before editing its variables. Separate configuration for unrelated apps and make the scope explicit when asking your agent for a change. build.host stores environment variables encrypted at rest; it does not make an unsafe frontend use of a secret safe.
When handing a project to another operator, document which variables it requires and where those values are configured. Share the setup instructions without copying credentials into a repository, template, or issue.
Apply the change and verify the connection
A redeployment is required to apply new environment-variable values. After it finishes, test the application flow that uses the changed setting. If the app still fails, inspect build and runtime logs and check the external service’s configuration.
Changing hosting configuration does not create a database, grant third-party permissions, or configure the service on the other end of a URL. Those dependencies need their own valid setup and verification.