SKILL.md
Environment Variables
Split Structure
This project uses split env files (see docs/PRDs/env-system-refactor.md):
| File | Purpose | Prefix |
|---|---|---|
.env.client |
Public browser vars | NEXTPUBLIC* |
.env.api |
Server secrets | No prefix |
Adding New Variables
Client-side (Public)
- Add to
.env.client:
`` NEXTPUBLICAPI_URL=https://api.example.com ``
- Access in code:
``typescript const url = process.env.NEXTPUBLICAPI_URL; ``
Server-side (Secret)
- Add to
.env.api:
`` STRIPESECRETKEY=sklivexxx ``
- Access only in server code:
``typescript // Only in app/api/, server/, or Server Components const key = process.env.STRIPESECRETKEY; ``
Security Rules
- Never put secrets in
.env.client - Never prefix secrets with
NEXTPUBLIC - Supabase anon key is public (safe for client)
- Supabase service role key is secret (API only)
Local Development
Copy example files:
cp .env.client.example .env.client
cp .env.api.example .env.api
Cloudflare Deployment
Set vars in Cloudflare Pages dashboard under Settings > Environment Variables.