Environment variables & secrets
Last updated 2026-10-07
Local runs read <project-root>/.env automatically (via the dotenv gem that ships with fastlane). In CI, set them as encrypted secrets. This follows fastlane's guidance on keys and secrets.
Warning: never commit secrets or put them in YAML or profiles.
my-app — zsh
~/my-app $ cp .env.example .env~/my-app $ grep -c "=" .env24~/my-app $ git check-ignore .env.envAndroid / Firebase
| Variable | Required | Purpose |
|---|---|---|
FIREBASE_TOKEN | Required when AI tests are on | Token from firebase login:ci. Takes priority over the service account. |
FIREBASE_SERVICE_CREDENTIALS_FILE | Required if no token | Path to service-account JSON (upload/distribution only) |
FIREBASE_STORAGE_BUCKET | Optional | e.g. your-project-id.appspot.com |
FIREBASE_ANDROID_<ENV>_APP_ID | Required (or google-services.json) | 1:123…:android:abc… per env (DEV, STAGING, UAT, PROD) |
FIREBASE_ANDROID_<ENV>_GROUPS | One of groups/testers | Tester group aliases, comma-separated |
FIREBASE_TEST_USERNAME / FIREBASE_TEST_PASSWORD | Optional | Login the AI agent uses |
iOS / App Store Connect
| Variable | Required | Purpose |
|---|---|---|
APP_STORE_CONNECT_KEY_ID | Required | API key ID |
APP_STORE_CONNECT_ISSUER_ID | Required (team keys) | Issuer ID |
APP_STORE_CONNECT_KEY_FILE | One of file/content | Path to AuthKey_XXXX.p8 |
APP_STORE_CONNECT_KEY_CONTENT | One of file/content | Raw .p8 content |
APPLE_TEAM_ID | Recommended | 10-character team ID |
MATCH_GIT_URL, MATCH_PASSWORD, MATCH_GIT_BRANCH | match only | Certificates repo |
Release metadata and notifications
| Variable | Purpose |
|---|---|
APP_ENV | Default environment when environment: is not passed |
VERSION_NAME | Version shown in names/messages; iOS also sets MARKETING_VERSION |
BUILD_NUMBER | Build number (falls back to GITHUB_RUN_NUMBER); iOS sets CURRENT_PROJECT_VERSION |
RELEASE_NOTES | Fixed release-notes text (overrides git) |
RELEASE_NOTES_FILE | Path to a release-notes file (overrides everything) |
TEAMS_WEBHOOK_URL | Teams Workflows webhook (Adaptive Cards) |
SLACK_WEBHOOK_URL | Slack webhook |
SMTP_HOST, SMTP_PORT, SMTP_USERNAME, SMTP_PASSWORD, SMTP_FROM, TEST_ALERT_EMAIL_RECIPIENTS | AI test report e-mail |
Official documentation
- fastlaneKeys and secretsdocs.fastlane.tools/best-practices/keys/
- GitHubUsing secrets in GitHub Actionsdocs.github.com/en/actions/security-for-github-actions/security-guides/using-secrets-in-github-actions
- FirebaseFirebase CLI referencefirebase.google.com/docs/cli
- AppleCreating API keys for App Store Connect APIdeveloper.apple.com/documentation/appstoreconnectapi/creating-api-keys-for-app-store-connect-api
Was this helpful?