- Put secrets in
.env.local, not in git. - Keep
.env.exampleas the shareable template. - Do not commit API keys, private keys, or wallet material.
OPENAI_API_KEYOPENAI_SECONDARY_API_KEYOPENAI_BACKUP_API_KEYOPENAI_FALLBACK_API_KEYODDPOOL_API_KEYPOLYMARKET_PRIVATE_KEYPOLYMARKET_CLOB_API_KEYPOLYMARKET_CLOB_API_SECRETPOLYMARKET_CLOB_PASSPHRASE
Run a quick scan for anything sensitive:
rg -n "sk-[A-Za-z0-9_-]{12,}|PRIVATE_KEY|API_KEY|PASS_PHRASE|passphrase|secret" .If you add a new secret-bearing setting later, update .gitignore, .env.example, and the docs together.