# Environments

The **Environments** page creates reusable environment configurations shared across MCP servers, most commonly for securely storing the secrets sources need to reach upstream systems. Open it from **MCP Gateway > Environments** in the project sidebar.

## Access requirements

> Viewing this page requires the `project:read` (or `project:write`) scope. Creating an environment, adding, editing, or deleting a variable, cloning an environment (which also needs `environment:read` on the source), and **Fill for MCP Server** require the `environment:write` scope. All access is included in the [default Admin role](/docs/ai-control-plane/org-admin/roles-and-permissions); Members can open the pages via `project:read`, but because environment values contain secrets, viewing values and all mutations require an explicit `environment:read` or `environment:write` grant.

## Environment list

Each environment card shows its name, description, and entry count, with actions to open or clone it. Search filters the list by name, slug, or description. Create environments with **New Environment** (requires environment write access).

**Clone** opens the **Clone environment** dialog, which asks for a new name and offers a **Copy stored secret values** toggle. Off, the clone copies only variable names with empty placeholders; on, it duplicates the encrypted secret values from the source. The clone opens as soon as it is created.

## Managing variables

Inside an environment, variables are listed with their keys and values. Sensitive entries are marked with a lock and a **Sensitive** badge; their values are masked, only ever return a redacted preview, and can't be copied out. A reveal toggle shows the masked preview inline.

**Add Variable** creates an entry with a name, a value, and a switch that marks it secret. Each row's menu offers **Edit**, **Copy to Clipboard** (disabled for secrets), and **Delete**. The page menu adds **Fill for MCP Server**, which prefills placeholder entries for everything a selected server needs: security variables, server variables, function variables, and headers. Placeholders are created as secrets with empty values, so fill them in before the server is used. Attach the environment to a built server from the server's **Authentication** tab; see [Configuring environments for functions](/docs/ai-control-plane/mcp-gateway/building-servers/functions/configuring-environments) and [Add tools from an OpenAPI spec](/docs/ai-control-plane/mcp-gateway/building-servers/openapi#step-3-set-environment-variables). The same menu holds **Delete Environment**.

Environments bind to hosted MCP servers so that secrets stay centralized instead of living in individual client configurations. See [Authentication](/docs/ai-control-plane/mcp-gateway#authentication) in the MCP Gateway overview for where an environment is attached to a server.
