Skip to main content
Nuxt Secure reads configuration from environment variables at runtime. Create a .env file in the project root before starting the development server.
Never commit your .env file to version control. Add .env to your .gitignore.

All environment variables

Example .env file

.env

How runtime config works

nuxt.config.ts reads each variable from process.env and maps it into Nuxt’s runtimeConfig:
nuxt.config.ts
In server routes and API handlers, access these values via useRuntimeConfig():
server/api/example.ts
Variables prefixed with NUXT_PUBLIC_ are exposed to the browser. Only place non-sensitive values there. All other runtimeConfig keys remain server-side only.

Variable details

A full PostgreSQL connection string in the format:
Nuxt Secure uses Neon serverless PostgreSQL. Copy this string from the Neon dashboard. See Database configuration for setup instructions.
A random string used to sign JWTs issued on login. If this value changes, all existing sessions are immediately invalidated.Generate a secure value with:
Credentials for the Cloudinary account used to store user profile photos. All three must be set together. If any are missing, profile photo uploads will not work, but the rest of the application will continue to function.See Cloudinary configuration for setup instructions.
The public site key for Cloudflare Turnstile. This value is exposed to the browser and used to render the CAPTCHA widget on the login page.See Cloudflare Turnstile for setup instructions.
The secret key for Cloudflare Turnstile. Used server-side to verify CAPTCHA tokens submitted with the login form. This value must never be exposed to the client.See Cloudflare Turnstile for setup instructions.