vibe-stack / rules
vibestackdev/vibe-stack/.cursor/rules/env-management.mdc
Environment variable management and secrets handling
Cursor rule8 starsChanged 6 months ago
- Reads credentials
What's in it
- Environment Variable Management
- Classification Rules
- NEVER Expose These to the Client
- Safe for Client
- Validation Pattern
- .env.local Structure
- Anti-Patterns
---
description: Environment variable management and secrets handling
globs: ["**/*.ts", "**/*.tsx", "**/.env*"]
alwaysApply: false
---
# Environment Variable Management
## Classification Rules
| Prefix | Visibility | Use For |
|--------|-----------|---------|
| `NEXT_PUBLIC_` | Client + Server | Non-sensitive public values (Supabase URL, Stripe publishable key) |
| No prefix | Server Only | ALL secrets (API keys, webhook secrets, database URLs) |
## NEVER Expose These to the Client
```
STRIPE_SECRET_KEY → Server only (NEVER NEXT_PUBLIC_)
STRIPE_WEBHOOK_SECRET → Server only
SUPABASE_SERVICE_ROLE_KEY → Server only (admin bypass key)
RESEND_API_KEY → Server only
DATABASE_URL → Server only
```
## Safe for Client
```
NEXT_PUBLIC_SUPABASE_URL → Public Supabase endpoint
NEXT_PUBLIC_SUPABASE_ANON_KEY → Rate-limited client key (RLS protects data)
NEXT_PUBLIC_STRIPE_PUBLISHABLE_KEY → Stripe public key (payment form only)
NEXT_PUBLIC_APP_URL → Your app's URL
```
## Validation Pattern
Use `src/lib/env.ts` to validate at startup:
```typescript
function getEnvVar(key: string, required = true): string {
const value = process.env[key]
if (!value && required) {
throw new Error(`❌ Missing required env var: ${key}`)
}
return value ?? ''
}
```
## .env.local Structure
```bash
# Supabase (required)
NEXT_PUBLIC_SUPABASE_URL=https://your-project.supabase.co
NEXT_PUBLIC_SUPABASE_ANON_KEY=eyJ...
# Stripe (optional in dev)
STRIPE_SECRET_KEY=sk_test_...
STRIPE_WEBHOOK_SECRET=whsec_...
NEXT_PUBLIC_STRIPE_PUBLISHABLE_KEY=pk_test_...
# Email (optional in dev)
RESEND_API_KEY=re_...
# App
NEXT_PUBLIC_APP_URL=http://localhost:3000
```
## Anti-Patterns
- NEVER commit `.env.local` — it's in `.gitignore`
- NEVER use `process.env.X` directly in components — use the centralized `env` config
- NEVER hardcode API keys or secrets in source code
- NEVER use `NEXT_PUBLIC_` for write-access API keys
More agent context in vibestackdev/vibe-stack
31 other files this repository gives its agents.
AGENTS.md
CLAUDE.md
Cursor rule
- .cursor/rules/ai-collaboration.mdc
- .cursor/rules/api-design.mdc
- .cursor/rules/api-validation.mdc
- .cursor/rules/caching-revalidation.mdc
- .cursor/rules/context-management.mdc
- .cursor/rules/database-design.mdc
- .cursor/rules/error-handling.mdc
- .cursor/rules/file-naming.mdc
- .cursor/rules/file-uploads.mdc
- .cursor/rules/git-conventions.mdc
- .cursor/rules/hydration-safety.mdc
- .cursor/rules/middleware-auth.mdc
- .cursor/rules/nextjs15-params.mdc
- .cursor/rules/performance.mdc
- .cursor/rules/project-context.mdc
- .cursor/rules/react19-patterns.mdc
- .cursor/rules/security.mdc
- .cursor/rules/server-actions.mdc
- .cursor/rules/server-vs-client-components.mdc
- .cursor/rules/shadcn-patterns.mdc
- .cursor/rules/stripe-payments.mdc
- .cursor/rules/stripe-webhooks.mdc
- .cursor/rules/supabase-auth-security.mdc
- .cursor/rules/supabase-rls.mdc
- .cursor/rules/supabase-ssr-only.mdc
- .cursor/rules/testing.mdc
- .cursor/rules/typescript-strict.mdc
- .cursor/rules/verify-before-use.mdc
llms.txt
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
Reports can't be read right now.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

