mcloud-variables

Execute mcloud variables commands to list and get environment variables for a Cloud environment. Use when inspecting, reading, or exporting environment…

npx skills add https://github.com/medusajs/medusa-agent-skills --skill mcloud-variables

Cloud CLI: Variables Commands

Execute mcloud variables commands to inspect and manage environment variables for Cloud environments.

Constraints

  • Never pass --reveal unless the user explicitly asks. Secret values appear in terminal scrollback, log aggregators, and process listings.
  • Variable changes need a deploy to apply. set/delete don't rebuild or redeploy. Run mcloud environments redeploy <env> for a runtime variable, or mcloud environments trigger-build <env> for a build variable (a redeploy reuses the existing image and won't pick up build-variable changes).
  • System variables can't be deleted, and delete requires --yes in non-interactive mode.
  • Looking up or creating a variable by key requires --project and --environment (or the equivalent in active context). Referencing by ID (var_...) works without project/environment context.
  • set and delete require mcloud CLI v0.1.10+.

Commands

variables list

List all environment variables for a Cloud environment.

mcloud variables list \
  --organization <org-id> \
  --project <project-id-or-handle> \
  --environment <environment-handle> \
  --json

Options:

  • -o/--organization <id> — Organization ID (falls back to active context)
  • -p/--project <id-or-handle> — Project ID or handle (falls back to active context)
  • -e/--environment <handle> — Environment handle (falls back to active context)
  • -t/--type <backend|storefront> — Which variable set to list (default: backend)
  • --scope <build|runtime> — Filter by scope; repeatable (default: both scopes)
  • --include-system — Include system variables Medusa auto-injects (default: false)
  • --reveal — Print secret values in plaintext instead of masking (use only when explicitly asked)
  • --dotenv — Output .env-formatted KEY=VALUE lines instead of a table
  • --json — Output as JSON

variables get

Retrieve a single variable by its ID (var_...) or key.

# By key (requires project + environment context)
mcloud variables get ADMIN_CORS \
  --organization <org-id> \
  --project <project-id-or-handle> \
  --environment <environment-handle> \
  --json

# By ID (works without project/environment context)
mcloud variables get var_01XYZ --json

Arguments:

  • variable — Variable ID (var_...) or key (required)

Options:

  • -o/--organization <id>, -p/--project <id-or-handle>, -e/--environment <handle>
  • -t/--type <backend|storefront> — Which variable set to read (default: backend)
  • --reveal — Print secret value in plaintext (use only when explicitly asked)
  • --json — Output as JSON

variables set

Create or update one or more variables. The CLI updates when you reference an existing key or a var_... ID, and creates otherwise.

# Single variable
mcloud variables set API_KEY pk_123 \
  --organization <org-id> \
  --project <project-id-or-handle> \
  --environment <environment-handle>

# Multiple at once
mcloud variables set -v API_KEY=pk_123 -v CLIENT_ID=my_app

# From a .env file
mcloud variables set --env-file .env

Arguments:

  • variable — Variable ID (var_...) or key to set (omit when using --var/--env-file)
  • value — Value to set (required when a variable argument is passed)

Options:

  • -o/--organization <id>, -p/--project <id-or-handle>, -e/--environment <handle>
  • -t/--type <backend|storefront> — Which variable set to write (default: backend)
  • -v/--var <KEY=VALUE|ID=VALUE> — A variable to set; repeatable
  • --env-file <path> — Set all variables from a .env file
  • --secret, --no-secret — Mark as secret (default: false for new variables)
  • --build, --no-build — Available at build time (default: false for new variables)
  • --runtime, --no-runtime — Available at runtime (default: true for new variables)
  • --json — Output as JSON

Redeploy (runtime) or trigger-build (build) afterward — see Constraints.

variables delete

Delete a variable by its ID (var_...) or key. Irreversible; system variables can't be deleted.

mcloud variables delete API_KEY \
  --organization <org-id> \
  --project <project-id-or-handle> \
  --environment <environment-handle> \
  --yes

Arguments:

  • variable — Variable ID (var_...) or key to delete (required)

Options:

  • -o/--organization <id>, -p/--project <id-or-handle>, -e/--environment <handle>
  • -t/--type <backend|storefront> — Which variable set to delete from (default: backend)
  • -y/--yes — Skip confirmation prompt (required in non-interactive mode)
  • --json — Output as JSON

Variable Fields (JSON)

FieldDescription
idVariable ID (var_...)
keyVariable name (e.g. ADMIN_CORS)
valueVariable value (masked if is_secret and --reveal not passed)
is_secretWhether the variable is treated as a secret
is_buildAvailable at build time
is_runtimeAvailable at runtime
environment_idThe environment ID this variable belongs to
sourceuser for user-set variables, system for auto-injected ones

Examples

# List all variables for the active environment
mcloud variables list --json

# List only runtime variables, including system ones
mcloud variables list --scope runtime --include-system --json

# List storefront variables
mcloud variables list --type storefront --json

# Get a variable by key (with active context)
mcloud variables get DATABASE_URL --json

# Get a variable by ID (no env context needed)
mcloud variables get var_01XYZ --json

# Set a single variable, then redeploy to apply (runtime)
mcloud variables set REDIS_URL redis://cache:6379
mcloud environments redeploy production

# Set a secret build-only variable, then trigger a build to apply
mcloud variables set STRIPE_SECRET_KEY sk_live_123 --secret --build --no-runtime
mcloud environments trigger-build production

# Set multiple variables from a .env file
mcloud variables set --env-file .env

# Delete a variable (irreversible — confirm before running)
mcloud variables delete OLD_FLAG --yes

# Only reveal secrets when user explicitly asks
mcloud variables get STRIPE_SECRET_KEY --reveal --json | jq -r '.value'

# Export all variables to a .env file (user must explicitly request --reveal)
mcloud variables list --reveal --dotenv > .env

# Check if a specific variable exists
mcloud variables list --json | jq '.[] | select(.key == "REDIS_URL")'

More skills from medusajs

building-storefronts
medusajs
SDK-first frontend integration for Medusa storefronts with React Query patterns and critical API calling rules. Always use the Medusa JS SDK for all API requests—never use regular fetch(), as it lacks required headers (publishable API key for store routes, auth for admin routes) Pass plain JavaScript objects to SDK methods; never use JSON.stringify() on body parameters, as the SDK handles serialization automatically Use useQuery for GET requests and useMutation for POST/DELETE requests,...
official
building-admin-dashboard-customizations
medusajs
Custom UI extensions for Medusa Admin dashboard using the Admin SDK and Medusa UI components. Load this skill FIRST for any admin UI work (planning, implementation, exploration); MCP servers provide API reference only, not design patterns or data loading strategies CRITICAL: Always use Medusa JS SDK for all API requests (never regular fetch); separate display queries from modal queries and invalidate display data after mutations Implement widgets on existing pages or create custom UI routes;...
official
learning-medusa
medusajs
Interactive step-by-step Medusa development bootcamp where you build a brands feature while learning architecture patterns. Three progressive lessons (2–3 hours total) covering modules, workflows, API routes, module links, workflow hooks, and admin UI customization Checkpoint verification after each major component tests conceptual understanding, code quality, and functionality before proceeding Treats errors as teaching opportunities; debugs together with diagnostic questions and root-cause...
official
db-migrate
medusajs
Execute pending Medusa database migrations and report results. Runs npx medusa db:migrate via Bash to apply all pending migrations to your Medusa database Reports migration outcomes including count of applied migrations, any errors encountered, and success confirmation Designed for Medusa projects with standard npm/npx setup
official
mcloud-environments
medusajs
Execute mcloud environments commands to list, get, create, delete, redeploy, or trigger builds for Cloud environments. Use when managing environment lifecycle,…
official
db-generate
medusajs
Generate database migrations for Medusa modules with a single command. Wraps the npx medusa db:generate CLI command to create migration files for specified Medusa modules Accepts module name as an argument and reports migration file location, errors, and next steps Automatically suggests running npx medusa db:migrate after generation to apply migrations
official
mcloud-deployments
medusajs
Execute mcloud deployments commands to list deployments, retrieve deployment details, and fetch build logs. Use when listing deployments, checking deployment…
official
building-with-medusa
medusajs
Comprehensive guide for Medusa backend architecture, workflows, and critical implementation rules. Covers six rule categories (architecture, type safety, business logic placement, imports, data access, file organization) with specific anti-patterns and enforcement checks Enforces strict layer separation: Module → Workflow → API Route → Frontend, with workflows required for all mutations and only GET/POST/DELETE HTTP methods allowed Includes critical data handling rules: prices stored as-is...
official