# Motoko-env a simple way to access environment variables

**URL:** <https://forum.dfinity.org/t/motoko-env-a-simple-way-to-access-environment-variables/42889>\
**Category:** Language Support\
**Tags:** Motoko\
**Created:** [March 22, 2025, 5:34pm UTC](https://forum.dfinity.org/t/motoko-env-a-simple-way-to-access-environment-variables/42889 "2025-03-22T17:34:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![demali.icp](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/demali.icp/32/14001_2.png) [@demali.icp](https://forum.dfinity.org/u/demali.icp)\
**Post date:** [March 22, 2025, 5:34pm UTC](https://forum.dfinity.org/t/motoko-env-a-simple-way-to-access-environment-variables/42889/1 "2025-03-22T17:34:04Z")

</div>

# 🛠 `motoko-env`: Environment Variable Parser for Motoko

Hey Motoko devs,

I recently audited a project and noticed they **hardcoded their API key** directly into the Motoko codebase 😅. Obviously, that’s not ideal — Motoko runs in an isolated environment, and **there’s no native support for `.env` files or environment variables** like we’re used to in other ecosystems.

To solve this, I built a simple tool: `motoko-env` – it parses your `.env` file and generates a Motoko module so you can access those values in your code.

## Installation

```bash
# Install globally
npm install -g motoko-env

# Or run directly without installing
npx motoko-env generate

```

* * *

## Usage

1. Create a `.env` file in your project root:

```auto
API_URL = https://example.com/api
CANISTER_ID = rrkah-fqaaa-aaaaa-aaaaq-cai

```

1. Generate the Motoko module:

```bash
npx motoko-env generate

```

1. Import and use in your Motoko code:

```motoko
import Env "../env";

actor {
  public func getApiUrl() : async Text {
    return Env.API_URL;
  };
}

```

Right now, it outputs everything as text, but I plan to support primitive type recognition(e.g. `Nat` `Int`, `Bool`, `Text`) in the near future.

I’m currently testing a Motoko implementation of **ChaCha20-Poly1305** for handling sensitive values like API keys. The goal is to **encrypt these values in JavaScript** and have **Motoko decrypt them at runtime**.

To ensure compatibility, the Motoko implementation must **match the expected test vectors defined in [RFC 8439](https://datatracker.ietf.org/doc/html/rfc8439)** — otherwise, decryption will fail.

You can view the library here [https://www.npmjs.com/package/motoko-env](https://www.npmjs.com/package/motoko-env). Please let me know what you think !

---

<div class="post-metadata">

**Author:** ![ggreif](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/ggreif/32/301_2.png) [@ggreif](https://forum.dfinity.org/u/ggreif)\
**Post date:** [March 22, 2025, 11:47pm UTC](https://forum.dfinity.org/t/motoko-env-a-simple-way-to-access-environment-variables/42889/2 "2025-03-22T23:47:51Z")

</div>

Hi @demali.icp, this is a cool utility, thanks for publishing it!

I still have the plan to have an official `import` facility in Motoko to obtain this (or similar) functionality…

Something like

```Motoko
import { API_URL : Text; CANISTER_ID : Principal } = "file:secrets.env";

```

with explicit bindings, or

```Motoko
import (Env : { API_URL : Text; CANISTER_ID : Principal }) = "file:secrets.env";

```

as a record to be used as you suggest above. One can dream…

---

<div class="post-metadata">

**Author:** ![demali.icp](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/demali.icp/32/14001_2.png) [@demali.icp](https://forum.dfinity.org/u/demali.icp)\
**Post date:** [March 23, 2025, 2:10am UTC](https://forum.dfinity.org/t/motoko-env-a-simple-way-to-access-environment-variables/42889/3 "2025-03-23T02:10:26Z")

</div>

Awesome, would love to see it once it’s ready. We should also make sure its included in the motoko docs as a resource for developers.
