All guidesBeginner guide
Beginner guide

Configure API Keys in VS Code

VS Code lets you store API keys in OS environment variables or a project .env file without committing them to the repository.

Related brands
VVS Code
Category
Beginner guide
Official sources
6
Read time
5 min
Last checked
2026.09.10
ANSWERStore API keys in a project .env file or register them in settings.json. Add .env to .gitignore to prevent leaks. Open a new terminal in VS Code and run echo %MY_API_KEY% (Windows) or echo $MY_API_KEY (macOS/Linux) to confirm the variable is set.

.env versus settings.json: where keys are stored

In VS Code, manage API keys per project using a root .env file or apply global settings via settings.json.

Configuration methodStorage locationScopeSecurity risk
Project .envProject root (.env)Current workspace onlyRisk of leak if .gitignore is missing
User settings.json%APPDATA%\Code\User\settings.jsonAll projects for the logged-in userRisk of leak during settings sync
OS global environment variableSystem environment variablesAll processes on the systemAccessible by other programs

Default paths for settings.json by OS are as follows. Windows stores it at %APPDATA%\Code\User\settings.json. macOS uses ~/Library/Application Support/Code/User/settings.json. Linux stores it at ~/.config/Code/User/settings.json.

Use the project .env method for quick tests. For system-wide integration, apply the OS environment variable method. Avoid writing keys directly into settings.json on shared PCs.

Minimal .env and .gitignore setup code

Open the terminal
Getting started with the terminal

To safely load API keys in a project, configure both the .env file and .gitignore defenses. Below is a minimal Node.js implementation using the dotenv package.


# .env file example

OPENAI_API_KEY="sk-proj-example-key-value"
API_REQUEST_TIMEOUT="5000"

# .gitignore file example

.env
.env.local
*.pem
// app.js execution example
require('dotenv').config();

const apiKey = process.env.OPENAI_API_KEY;
if (!apiKey) {
  console.error('Error: OPENAI_API_KEY environment variable is not set.');
  process.exit(1);
}
console.log('API key loaded:', apiKey.substring(0, 7) + '...');

From opening a folder to verifying key registration

Follow these steps to register an API key using VS Code’s internal terminal, environment files, and settings UI.

  1. Open File > Open Folder in VS Code, select your project directory, and create a .env file in the Explorer pane.
  2. Inside the new .env file, enter API_KEY=your_actual_key_here and save the file.
  3. In the Explorer pane, create or open .gitignore and add .env to exclude it from Git tracking.
  4. Press Ctrl+Shift+P (macOS: Cmd+Shift+P) to open the Command Palette and select Preferences: Open User Settings (JSON).
  5. Add the line "terminal.integrated.env.windows": { "MY_API_KEY": "your_actual_key_here" } to settings.json and save.
  6. Open Terminal > New Terminal from the top menu, then run echo %MY_API_KEY% (Windows cmd) or echo $MY_API_KEY (Bash/zsh) to verify the value.

If the terminal displays the configured your_actual_key_here value, the environment variable is applied correctly.

Values that must never reach source code or public repos

Never hardcode API keys directly inside source files (.js, .py, .java, etc.). If a key is embedded in source code, it becomes permanently exposed in Git history when committed.

When pushing code to public repositories (GitHub, GitLab, etc.), ensure .env files, certificate files (.pem, .p12), and local database passwords are excluded from tracking. Explicitly list these extensions and filenames in .gitignore.

If using an organizational account, terminal environment variable injection may be restricted by admin console policies. When transmitting confidential company data to an external AI model API, obtain prior approval from the security team and review the transmission scope.

Fixing undefined values and unread .env files

If an undefined error occurs despite setting the environment variable, confirm whether the terminal session was opened before the variable was configured. VS Code’s integrated terminal loads environment variables only at session creation, so always open a new terminal via Terminal > New Terminal after modifying settings.json.

If the .env file is not recognized, verify that the script execution path matches the .env file location. Running a script from a subdirectory outside the project root can prevent dotenv from locating the file.

If a .env file has already been committed to the Git repository, adding it to .gitignore afterward does not remove it from tracking. Run git rm --cached .env in the terminal to remove the file from the Git index, then commit.

If an API key is already exposed, log in to the provider’s console and immediately revoke and reissue the key. When requesting official support or community help, mask the actual key string and share only the configuration structure.

If a shortcut does not respond, open View > Command Palette from the top menu and run the same command from there.

Revision history

This article was revised against the provider’s official documentation. Korean note

Sources

code.visualstudio.com — Get started with Visual Studio Code (2026-08-22)

code.visualstudio.com — VS Code extension marketplace (2026-08-22)

code.visualstudio.com — Download Visual Studio Code - Free AI Code Editor for Mac ... (2026-08-22)

code.visualstudio.com — Visual Studio Code - The open source AI code editor | Your ... (2026-08-22)

visualstudio.microsoft.com — Visual Studio: IDE and Code Editor for Software Development (2026-08-22)

visualstudio.microsoft.com — Visual Studio Downloads for Windows (2026-08-22)

Open provider document
Next guideUse Copilot in Excel for Data Analysis and Formulas