API: PATCH https://api.deno.com/v2/apps/{appId} (env_vars deep-merged by key); org-wide via PATCH https://api.deno.com/v2/layers/{layerId}; set secret:true to mask values in future responses; contexts is "all" or an explicit array.
Build-context vars apply only during builds; redeploy/next build pickup is generally required for new variables to take effect.
Official docs: https://docs.deno.com/deploy/reference/env_vars_and_contexts/ ; https://docs.deno.com/runtime/reference/cli/deploy/
Known gotchas
Contexts are a common silent failure: Production vars serve production traffic, Development vars serve preview/branch timelines, Build vars exist only at build time.
Secrets are write-only after creation - never visible in UI or API afterward; you can only update or delete them.
Variables exist at app level AND organization (layer) level; org vars flow down but can be overridden per app - check both when a value looks wrong.
This contexts/layers model is specific to the current platform and differs from Deploy Classic's flat env list (Classic discontinued July 20, 2026).
Give your agent this knowledge — and 17,900+ more routes
One MCP install gives any agent live access to the full route map across 6,000+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?