Nuxt warnings
dotenv-diff includes Nuxt-specific rules to catch unsafe or unreliable environment variable usage. This page reflects the currently implemented rules and targets Nuxt 3.
Background
Nuxt exposes runtime configuration through runtimeConfig (private, server-only)
and runtimeConfig.public (exposed to the client), accessed via useRuntimeConfig().
In production, .env files are not read at runtime, and process.env is not populated in the browser. Environment variables only override runtime config when prefixed
with NUXT_ (private) or NUXT_PUBLIC_ (public).
1. process.env in client/universal code
process.env is unreliable outside server code. It is not available in the browser, and .env files are not read at runtime in production.
dotenv-diff warns:
process.env is not available in the browser; use useRuntimeConfig() instead
2. Sensitive names in NUXT_PUBLIC_ variables
If a NUXT_PUBLIC_ variable contains SECRET, PRIVATE or PASSWORD, dotenv-diff warns
— these values are exposed to the browser.
Warning:
Potential sensitive environment variable exposed to the browser
What Is Allowed
process.env is allowed in server only contexts without framework warnings:
- The Nitro
server/directory (server/api,server/routes,server/middleware, etc.) - Files with a
.server.suffix, for exampleplugins/auth.server.ts nuxt.config.ts, where env vars feedruntimeConfig
Summary of All Rules
- process.env in client/universal code → use useRuntimeConfig()
- Sensitive names in NUXT_PUBLIC_* → warning
Best Practices
- Use
runtimeConfig/useRuntimeConfig()instead of reading process.env directly in app code. - Only put browser-safe values under
runtimeConfig.public/NUXT_PUBLIC_*. - Keep secrets in server-only code paths (
server/,.server.files).