Documentation
How to Set Project Environment Variables
Environment variables store a secret outside the files visitors download. Static HTML and JS stay public after deploy, so a key pasted there is effectively shared.
Add a variable
- Open project settings in editor.clincoo.buzz, or ask the AI assistant to add an env var.
- Name it in uppercase with underscores, for example MAIL_API_KEY. Do not use spaces.
- Paste the value once. Do not send that same value to a general chat or a README.
Use the value without leaking it
Server code or a terminal command may read the variable. The index.html file sent to the browser must not. If a service has to be called from a static page, pass the call through an endpoint that holds the secret, not through a key in the frontend.
Test, then deploy again
- Ask the assistant to check that the secret is set, without printing it to the log.
- If a new value is not picked up, save again and redeploy — a running process still holds the old value.
- Rotate the key at the provider if that value was ever written in a public file.