How it works
An app reads values such as DATABASE_URL or STRIPE_SECRET_KEY from its environment when it starts (process.env in Node.js, os.environ in Python). Locally they usually live in a .env file that is kept out of Git; in production they are set in the host's dashboard or a secrets manager. The same build can then use a test database in staging and the real one in production.
Frameworks decide which variables reach the browser. In Next.js only names starting with NEXT_PUBLIC_ are bundled into client code, and in Vite only those starting with VITE_; anything bundled is visible to every visitor, so secret keys must stay on the server. A committed .env file is one of the most common ways secrets leak, and a .env.example file with dummy values is the usual way to document what is needed.
Related terms
More in Dev workflow and DevOps
Environments