Fork it, deploy it, own it
A tool that only runs on your laptop is a script. This lesson puts yours at a URL, with the key safe, in about fifteen minutes.
Your repository, not a copy of someone else's
Fork the starter so the result is yours: your history, your commits, your ability to change anything without asking. You have been committing all along, and this is where that becomes a portfolio artefact rather than a folder.
The key moves, it does not travel
This is the moment people leak keys, so be deliberate.
Your .env.local is gitignored and stays on your machine. It is not uploaded, and it must not be committed as a convenience "just for deploy". On the host, the same variable is entered separately in the project's environment settings, where it is stored by the platform and injected at runtime.
Two variables, one name, two places, never in git. If you ever find yourself pasting a key into a file to make a deploy work, stop: the deploy has an environment settings page, and that is what it is for.
Deploy
With Vercel, importing the forked repository is a wizard: it detects Next.js, asks for environment variables, builds, and gives you a URL. Add EODHD_API_KEY when asked. That is the entire deployment.
Then verify, in this order:
- The page loads and shows your instruments. Data flowing means the key reached the server.
- Open developer tools, network tab, and look at every request the browser made. No request should go to
eodhd.com. Everything market-related goes to your own/api/proxy/.... If you see a direct call, something in your code is fetching client-side, and your key is in that request. - Search the page source for your key. Nothing.
Step 2 is the one people skip and the only one that checks the actual promise of this whole course.
Make the check automatic
You will change this code again, probably with an assistant, probably in a hurry. Add a CI check so the machine enforces what you currently remember:
# .github/workflows/key-leak.yml
name: key leak
on: [push, pull_request]
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Refuse key-shaped strings in tracked files
run: |
if git grep -nIE '[0-9a-f]{12,}\.[0-9]{6,}' -- . ':(exclude)package-lock.json'; then
echo "A key-shaped string is committed. Rotate it, then remove it."
exit 1
fi
Your pre-commit hook catches what you stage on your own machine. This catches what arrives from anywhere, including a commit made by an assistant, and it keeps working when you forget.
Who is allowed to look at it
Your deployment has a public URL. That has two consequences worth thinking about for a minute.
Anyone with the link can spend your quota. Every visit is calls against your allowance. Add access control, keep the URL private, or accept it deliberately.
Showing market data to other people is a different licence. EODHD's plans are, in their own words, "intended for personal use only as commercial use requires a more thorough approach to licensing and data use". A tool you use is personal use. A public page where other people read the numbers is not, and the licence page in this lesson's sources is where that conversation starts.
Try it now
Deploy, then run the network-tab check on the live URL, on your phone as well as your laptop. Then do the destructive test on a branch: deliberately add a client-side fetch to eodhd.com, push it, and confirm your CI scan or your own review catches it before it reaches main. Delete the branch. You have now tested the safety net rather than assumed it.