← All guides

Secrets guide

Environment variables checklist for AI-built apps

VercelVPSSupabase

Short answer

A clean env-var map for local, preview, and production with secrets rotated where needed.

Why this matters

The app worked locally, but production fails because keys are missing, public/private vars are mixed, or callbacks still point to old URLs.

Walkthrough

  1. 01

    Separate public and private variables

    Browser-exposed variables are not secrets. Server-only variables must never be shipped to the client.

    • Mark public frontend variables separately from server secrets.
    • Keep database passwords, service role keys, webhook secrets, and private API keys server-only.
    • Do not paste production secrets into screenshots, public repos, or AI prompts.
  2. 02

    Update URLs for the final domain

    Every service that redirects back to your app needs the production domain.

    • Update OAuth callback URLs, Supabase auth redirects, Stripe webhook endpoints, and email link domains.
    • Remove old preview domains when they are no longer needed.
    • Test login, payment webhooks, and password reset after DNS cutover.
  3. 03

    Rotate anything exposed

    If a secret touched a public repo, leaked build log, browser bundle, or chat transcript, treat it as burned.

    • Rotate leaked keys before launch.
    • Delete old keys after the new deployment is verified.
    • Store final values in the deployment panel or server environment, not in source code.

Where RepoAssistant fits

RepoAssistant cleans up production env vars during deploy so launch does not fail on hidden secrets.