Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In a Declarative Jenkins Pipeline, set variables in an environment block: put it directly inside pipeline for Pipeline-wide scope, or inside a stage for stage-only scope. In a Scripted Pipeline, wrap the steps that need a value in withEnv(['NAME=value']). Read values as env.NAME in Pipeline Groovy and use the relevant shell’s syntax inside shell commands.

Set a variable in a Declarative Pipeline

An environment block defines environment variables for the steps in its scope. Use a top-level block when multiple stages need the same value:

pipeline {
    agent any
    environment {
        BUILD_MODE = 'release'
    }
    stages {
        stage('Build') {
            steps {
                echo "Mode: ${env.BUILD_MODE}"
                sh 'make BUILD_MODE=$BUILD_MODE'
            }
        }
    }
}

In Groovy Pipeline code, access the value as env.BUILD_MODE. The single-quoted sh command is passed to the shell, which expands $BUILD_MODE.

Limit a variable to one stage

Place the block inside the stage to scope the value to that stage’s steps:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
pipeline {
    agent any
    stages {
        stage('Test') {
            environment {
                TEST_FLAGS = '--verbose'
            }
            steps {
                sh 'make test TEST_FLAGS="$TEST_FLAGS"'
            }
        }
    }
}

The quoted shell expansion keeps the value together if it contains spaces. Adapt quoting and variable expansion to the command and shell used by the agent.

Set a variable in a Scripted Pipeline

Use withEnv to make a value available to the steps inside its wrapper:

node {
    withEnv(['BUILD_MODE=release']) {
        sh 'make BUILD_MODE=$BUILD_MODE'
    }
}

Values set with withEnv are available to external processes started within that wrapper. Its special forms also let you temporarily unset a variable with NAME=, or prepend a directory to PATH with PATH+LABEL=/directory. For example:

node {
    withEnv(['TEMP_SETTING=', 'PATH+TOOLS=/opt/tools/bin']) {
        sh 'echo "$PATH"'
    }
}

Choose the right source and scope

Need Use Where it applies
Ordinary configuration in Declarative Pipeline environment { NAME = 'value' } All Pipeline steps when top-level; one stage’s steps when stage-level
Ordinary configuration in Scripted Pipeline withEnv(['NAME=value']) Steps inside the wrapper
A value chosen when the build starts Pipeline parameter Available as an environment variable to steps and through the read-only params map in Pipeline Groovy
A secret such as a token Configured Jenkins credential Bind by credential ID; use scoped credential bindings where appropriate

Use credentials for secrets

Do not put passwords, tokens, or other secret values directly in a Jenkinsfile. For supported credential types, Declarative Pipeline can bind a configured credential by ID in an environment block:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
pipeline {
    agent any
    environment {
        API_TOKEN = credentials('api-token-credential-id')
    }
    stages {
        stage('Call service') {
            steps {
                sh 'some-command --token "$API_TOKEN"'
            }
        }
    }
}

Use the configured Jenkins credential ID in place of the example ID. Jenkins also documents withCredentials for other credential bindings and scoped access. A username/password binding can expose a combined value and separate _USR and _PSW variables.

Secret masking can reduce accidental exposure in logs, but it cannot prevent a Pipeline from disclosing a credential. Do not let untrusted Pipeline jobs use trusted credentials. In particular, avoid Groovy-interpolated command strings for commands that use secrets: pass a literal string to sh so the shell reads the value from its environment rather than Groovy inserting secret material into command arguments.

“A Pipeline that uses credentials can also disclose those credentials.” — Jenkins, Using a Jenkinsfile documentation.

Use parameters and read values in commands

Pipeline parameters are exported as environment variables when a build starts. In Pipeline Groovy, use the read-only params map to access parameter values. In a shell step such as sh, use that shell’s variable expansion syntax; for PowerShell or Windows cmd.exe, use the syntax for the command shell actually running on the agent.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Pipeline Groovy: env.BUILD_MODE
  • POSIX shell in sh: $BUILD_MODE or ${BUILD_MODE}
  • Shell commands: prefer literal Groovy strings when the shell should expand environment variables, especially when secrets are involved.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot common problems

  • The variable is empty in another stage: check whether its environment block is inside a different stage. Move it to the top-level block if all Pipeline stages need it.
  • The variable is unavailable outside a Scripted wrapper: withEnv scopes the variable to the wrapped steps. Put every step that needs it inside the wrapper.
  • Groovy prints an unexpected value: read the Pipeline environment through env.NAME; for build parameters, use params.NAME.
  • The shell sees a literal dollar sign or an empty value: check which shell step and shell syntax the agent uses, and ensure Groovy has not interpolated or altered the command string before the shell receives it.
  • A secret appears in output or arguments: avoid Groovy interpolation, use Jenkins credential bindings, and do not expose trusted credentials to untrusted Pipeline code. Masking is not a security boundary.

Or skip the browser setup

If your separate task is capturing website screenshots, ScreenshotNeo offers a one-request API. The following cURL command saves a WebP screenshot of Stripe; create an API key and replace the placeholder value. See the ScreenshotNeo documentation for API options.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo accepts cookie or consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; those steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers report the page verdict and billing status. Its MCP server provides screenshot tools for AI agents, and the free plan includes 1,000 shots per month without a card; paid plans start at $5 for 3,000 shots.

Sign up for ScreenshotNeo’s free plan to try 1,000 screenshots a month with no card.

Frequently Asked Questions

Can a Pipeline parameter be read both as an environment variable and in Groovy?

Yes. Jenkins exports build parameters to the environment for steps and exposes them in Pipeline Groovy through the read-only `params` map.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does masking make a credential safe in an untrusted Pipeline?

No. Masking may reduce accidental log exposure, but a Pipeline can still disclose credentials. Do not make trusted credentials available to untrusted Pipeline jobs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.