Docs
Reference

Heroku config vars

Move secrets to and from one Heroku app's config vars.

Move secrets to and from one Heroku app's config vars.

The connection

WhatThis provider
VendorHeroku
Keyheroku-config-vars
Availabilityavailable. You can connect it today.
Credential penv holdsheroku-token
Values read backyes
Activationrestart-on-write

What it moves

DirectionWhat it does
importReads names and values out of the store into penv.
exportWrites names and values from penv into the store.

When a written value goes live

restart-on-write. Writing a value restarts the workload.

What happens to a name that exists

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

How you connect

You paste a credential you already hold. penv seals it and never shows it again.

FieldLabelKindRequiredWhat it is
tokenHeroku API tokensecret, masked here and sealedyesNeeds global or write-protected scope. A write token can deploy the app but cannot touch its config vars.

What a mapping asks for

Answered once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
appApptextyesnoOne app per sync. Changing a config var restarts it.

Permissions it needs

penv probes for these when it verifies the connection.

PermissionDirectionsBlockingWithout it
apps:readevery directionyesThe token cannot reach your apps at all.
read-protectedimportyesImport cannot read config vars, because a plain read token is refused for them.
write-protectedexportyesExport cannot write anything.