← All guides
Secrets guide
Environment variables checklist for AI-built apps
VercelVPSSupabase
Short answer
A clean env-var map for local, preview, and production with secrets rotated where needed.
Why this matters
The app worked locally, but production fails because keys are missing, public/private vars are mixed, or callbacks still point to old URLs.
Walkthrough
- 01
Separate public and private variables
Browser-exposed variables are not secrets. Server-only variables must never be shipped to the client.
- Mark public frontend variables separately from server secrets.
- Keep database passwords, service role keys, webhook secrets, and private API keys server-only.
- Do not paste production secrets into screenshots, public repos, or AI prompts.
- 02
Update URLs for the final domain
Every service that redirects back to your app needs the production domain.
- Update OAuth callback URLs, Supabase auth redirects, Stripe webhook endpoints, and email link domains.
- Remove old preview domains when they are no longer needed.
- Test login, payment webhooks, and password reset after DNS cutover.
- 03
Rotate anything exposed
If a secret touched a public repo, leaked build log, browser bundle, or chat transcript, treat it as burned.
- Rotate leaked keys before launch.
- Delete old keys after the new deployment is verified.
- Store final values in the deployment panel or server environment, not in source code.
Where RepoAssistant fits
RepoAssistant cleans up production env vars during deploy so launch does not fail on hidden secrets.