Do this once per process before any upload, admin, or URL-generation call.
Prerequisite: a cloud_name, api_key, and api_secret. If you do not have them,
see Get Cloudinary credentials — npx @cloudinary/cloud provisions
a working cloud with no signup.
Set CLOUDINARY_URL (from Console > Settings > API Keys, or written into .env for you
by npx @cloudinary/cloud):
export CLOUDINARY_URL=cloudinary://<api_key>:<api_secret>@<cloud_name>require "cloudinary"
# Configuration is read from CLOUDINARY_URL automatically on first use.
puts Cloudinary.config.cloud_namerequire "cloudinary"
Cloudinary.config do |config|
config.cloud_name = "my-cloud"
config.api_key = ENV["CLOUDINARY_API_KEY"]
config.api_secret = ENV["CLOUDINARY_API_SECRET"]
config.secure = true
endCloudinary.config(hash) sets the same values from a hash.
Rails apps can keep settings in config/cloudinary.yml, keyed by environment. See
Use with Rails — including why credentials belong in
CLOUDINARY_URL or Rails encrypted credentials rather than in that file.
Verified against this version, highest priority first:
- Per-call options — any option passed to a method overrides config for that call.
Cloudinary.configassignments made at runtime.- Discrete
CLOUDINARY_*environment variables (CLOUDINARY_CLOUD_NAME,CLOUDINARY_API_KEY, ...). CLOUDINARY_URL.config/cloudinary.yml, section matchingCLOUDINARY_ENVorRails.env.
Trap: if
CLOUDINARY_CLOUD_NAMEis set,CLOUDINARY_URLis ignored completely — not merged. The SDK then takes every other value from the discrete variables or the YAML file, so a staleapi_keycan survive whilecloud_namelooks correct. Use one mechanism or the other, not both.
- Configuration is process-global:
Cloudinary.configaffects every caller in the process. Pass per-call options as the trailing hash when you need to override one call. - Delivery URLs are HTTPS by default in this SDK; you do not need
secure: true. Passsecure: falseto get anhttp://URL. - Generated URLs carry an
?_a=SDK-analytics parameter. It does not affect delivery or caching. Disable per call withanalytics: false. - Account-level (provisioning) operations read
CLOUDINARY_ACCOUNT_URLthroughCloudinary.account_config. - Proxy support: set
api_proxyin config.
%w[cloud_name api_key api_secret].each do |key|
raise "Cloudinary is not configured: set CLOUDINARY_URL (missing #{key})" if Cloudinary.config.send(key).nil?
endMust supply cloud_name/Must supply api_key—CLOUDINARY_URLis missing or malformed; it must start withcloudinary://. Note the exception class differs by entry point; see Troubleshoot errors.Invalid Signatureon uploads — a wrongapi_secret. Uploads report it this way instead of naming the secret.- Config silently empty in a Rails app — the
cloudinary.ymlsection name must matchRails.env; a file with only adevelopment:key gives nothing undertest.
- Get Cloudinary credentials — if you do not have an account yet.
- Sign a browser upload — keeping the secret server-side.
- Use with Rails