Env vars for APIs
API keys live in env vars, never in source code.
Difficulty 2/5
Short
Plain English
API keys live in env vars, never in source code. Picture it like this: Keep keys off the keyring you leave on the bar. In the apps you ship (Agentify, wedding portals, CRM), you will bump into this on almost every screen — name it clearly when you prompt your coding agent.
Analogy
Keep keys off the keyring you leave on the bar.
Go deeper
API keys live in env vars, never in source code.
Common mistakes
- Letting the AI rename this concept three different ways in one PR.
- Building UI before you can say what is stored and who can change it.
AI-agent trap
Agents may invent jargon here. Ask them to explain the concept in plain English first, then map it to your schema and one real screen.
Summary
API keys live in env vars, never in source code. Keep keys off the keyring you leave on the bar. Ask yourself: where does this live in the database, which function changes it, and which screen shows it?
Confidence: