‹ Ship Your Tool Lesson 3 of 16
Contents Lesson 3 of 16

4 min read · professional

Configuration for someone else's machine

Your tool has your key, your symbols, your assumptions about ports. This lesson separates what is yours from what is the tool's.

Everything environment-specific comes from environment

API key, base URL, port, store connection. Nothing environment-specific is a literal in the code, and one file lists every variable that exists:

# .env.example — copy to .env.local and fill in
EODHD_API_KEY=            # free key from the pricing page
EODHD_BASE_URL=https://eodhd.com/api

.env.example is committed and holds no secrets: the key line is empty, and the non-secret lines carry their working defaults, as the base URL above does. .env.local holds your real values and is gitignored. That pair is the whole convention, and the starter repository ships it already.

Fail loudly at boot, not quietly at request time

A missing key should stop the application starting, with a message that names the variable and the file:

if (!process.env.EODHD_API_KEY) {
  throw new Error("EODHD_API_KEY is not set — copy .env.example to .env.local");
}

The alternative is a tool that starts, renders, and shows empty panels — and the person concludes the tool is broken rather than unconfigured. Ten seconds of confusion at boot beats twenty minutes of confusion in the browser, and this is the single highest-return five lines in the course.

The key is still not in the bundle

Nothing about shipping changes course 1's rule. EODHD_API_KEY has no public prefix, is read only on the server, and the proxy is still the only thing that touches it.

Two extra habits once the repo is public:

  • Check the git history, not just the working tree. A key committed and then deleted is still in the history and still needs rotating. git log -p piped through the same pattern your pre-commit hook uses takes a minute.
  • If a key was ever exposed, rotate it. Not "it was only briefly public". Rotating is free and takes a minute; assuming nobody looked is a bet you cannot check.

Sensible defaults so it runs on first try

Every variable except the key should have a working default. A person who supplies one secret and gets a running application has had a good first experience; one who has to fill in six fields before seeing anything has had a chore.

Same principle as the default layout from course 4: nobody should meet an empty form before they have seen the thing work.

Try it now

Delete your .env.local, start the app, and read what it tells you. If the message does not name both the variable and the file to create, fix it — that message is the first thing every future user of your tool will read.