Reference for netlify.toml configuration and site environment variables. Use when configuring build settings, redirects, rewrites, headers, deploy contexts, the `[dev]` block that controls `netlify dev` (command, port, targetPort, framework), or any site-level configuration — and when managing environment variables or secrets with the Netlify CLI, including scoping values to specific deploy contexts. Covers the complete netlify.toml syntax including redirects with splats/conditions, headers, deploy contexts, functions config, edge functions config, and the `[dev]` block (including when `framework` must be `"#custom"` — required when both a custom `command` and `targetPort` are set).
87
92%
Does it follow best practices?
Impact
92%
1.14xAverage score across 2 eval scenarios
Passed
No findings from the security scan
Netlify SPA redirect ordering and context scoping
API proxy before SPA catch-all
100%
100%
SPA catch-all status 200
100%
100%
force = true for static file override
0%
100%
No context-nested redirects
100%
100%
Redirects-global explanation
100%
100%
Workaround for context-specific redirects
90%
100%
Rule-order rationale
100%
100%
CDN-only headers
60%
50%
Security headers present
100%
100%
Secure env var management for Netlify project
No secret in netlify.toml
100%
100%
Secret set via CLI
100%
100%
Secret flag used
100%
100%
Context scoped to production
50%
100%
Local .env export command
12%
0%
.env gitignore warning
100%
100%
No secret in VITE_ prefix
100%
100%
Client-prefix exposure warning
100%
100%
toml vars build-scoped warning
50%
100%
CLI vars available at runtime
75%
100%
toml precedence noted
0%
66%
b4ac277
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.