How to see a Lambda function's environment variable names without showing their values

Updated · 2 min read

You want to know what a function is configured with (does it have a DATABASE_URL? which STRIPE_ keys?) without putting secret values on your screen, in your terminal's scrollback or in a screen share. The Lambda console shows names and values together, and AWS's API has no names-only option.

In the AWS console

Lambda → your function → Configuration → Environment variables lists every variable with its value in plain text, and there's no way to hide the values in that view. If you're sharing your screen, check what's on it before you click.

The exception is values encrypted with the console's encryption helpers (encryption in transit). Those show as ciphertext, and the function's code decrypts them itself.

With the AWS CLI

The API still returns names and values together, but the CLI's --query option can keep only the names before anything is printed:

aws lambda get-function-configuration --function-name my-function \
  --query 'keys(Environment.Variables || `{}`)'

The || `{}` part handles functions that have no variables at all, which would otherwise make keys() fail.

For every function in a region:

aws lambda list-functions --region us-east-2 \
  --query 'Functions[].[FunctionName, join(`, `, keys(Environment.Variables || `{}`))]' \
  --output text

The values still travel from AWS to your machine (the filtering happens inside the CLI), but they never reach your screen or your scrollback. Don't add --debug to these commands: it prints the full responses.

Why IAM can't hide the values

Anyone allowed to call lambda:GetFunctionConfiguration or lambda:ListFunctions receives the values too, including anyone with AWS's own ReadOnlyAccess policy. There's no permission for names without values. So:

  • Keep secrets out of environment variables. Put them in Secrets Manager or SSM Parameter Store and put only the secret's name in the environment variable. Reading the secret then takes its own permission, which you give to the function and not to everyone who can look around the account.
  • Treat "can list functions" as "can read their configuration". That includes monitoring tools and read-only roles you've given to third parties.

Or in Cloud GUI

Cloud GUI shows each function's environment variable names, never the values. AWS sends the values when Cloud GUI lists your functions (the same IAM limitation applies to everyone), so Cloud GUI drops them on its server before anything is shown or cached. Its security page says so plainly, along with everything else it can and can't see.

See your whole AWS account in one calm view

Cloud GUI shows your files and functions from every region at once, in plain English, with what's failing up front. It connects with a read-only role you create and can delete any time. Free for one AWS account.

More guides

Free tool
IAM policy explainer

Paste an IAM policy and read it in plain English, with the risky parts flagged. It runs in your browser; nothing is sent anywhere.