hackhaton-space-stackHackhaton Space Stack
AcademyBuilder
Get Started
All terms
The Basics
  • Stack
  • Frontend & Backend
  • CLI
  • Monorepo
  • Server
  • Localhost
How AI Works
  • Context Window
  • Hallucination
  • Token
  • Prompt Caching
  • Session
  • Compaction
  • Embedding
  • Vector Database
  • RAG
  • Fine-tuning
  • Temperature
  • Inference
  • Reasoning
  • Multimodal
Building With AI
  • Agent
  • MCP
  • System Prompt
  • Skill
  • CLAUDE.md
  • Slash Command
  • Harness
  • Computer Use
  • Agents SDK
  • Voice Agents
  • OAuth
  • Vibe Coding
  • Permission Scope
  • Tool Calling
  • Prompt Injection
  • Eval
  • Guardrails
  • Sandbox
  • Progressive Disclosure
Code & Collaboration
  • Git
  • Commit
  • Branch
  • GitHub
  • Pull Request
  • Open Source
  • Markdown
  • Dependency
  • Merge
  • Fork
APIs & Connections
  • API
  • Auth
  • Database
  • ORM
  • SDK
  • Webhook
  • Endpoint
  • REST
  • HTTP Methods
  • Env File
  • Schema
  • JSON
  • YAML
  • Secret
  • Rate Limit
  • CORS
  • Cookie
  • Encryption
Shipping & Running
  • Deploy
  • Headless
  • Cron
  • DNS
  • CDN
  • Object Storage
  • Serverless
  • Edge
  • Worker
  • Runtime
  • Process
  • Daemon
  • Queue
  • Job
  • State
  • Cache
  • SSH
  • Build
  • Staging
  • Rollback
  • Docker
  • Feature Flag
  • Test
  • CI/CD
  • The Cloud
Debugging & Errors
  • Trace
  • Type Error
  • Stack Trace
  • Log
  • Bug
  • Patch
  • Latency
How Developers Think
  • DRY
  • YAGNI
  • KISS
  • Refactoring
  • Technical Debt
  • Async
← All terms

Type-safe, modern TypeScript scaffolding for full-stack web development

ThreadsGitHub

Info

  • Academy
  • Docs

Legal

  • Terms of Service
  • Privacy Policy

© 2026 Dzulhelmy Nazri

APIs & Connections

$definesecret--plain-english

Secret

TLDRA string that must stay hidden or someone else can act as you.

A public string says who something is. A secret proves you are allowed.

API keys. Session tokens. Private keys. Database passwords. Hold one and you can spend, delete, or impersonate. That is the whole difference. NEXT_PUBLIC_SITE_URL can be in the repo. STRIPE_SECRET_KEY cannot.

Where it lives

In an env file on your laptop. In the host's vault after deploy. Never in the route. Never in a screenshot for Discord. Never in the chat log you paste into a GitHub issue. Bots scan public repos for exactly these strings. They are faster than you.

The builder will create .env.example with names. Fill the real file locally. Tell your agent the name of the variable, not the value. If it echoes a key, rotate it. Treat the leak as done, not theoretical.

If it got out

Rotate. Cancel the old key. Issue a new one. Update .env and the host. Do not "watch for a bit." A leaked Stripe key at a hackathon is a real bill.

Give each key the least power it needs. A publishable key in the browser is not the secret key. Do not copy the wrong one into NEXT_PUBLIC_ and ship it to every judge's tab.

Encryption hides a secret on the wire. It does not forgive a commit. The CLI can scaffold the files. It cannot unsay a push.

What this unlocks

You can open-source the app and still own the account.

Show the public strings. Hide the keys. Rotate when you slip.

Related

  • Env File
  • API
  • GitHub
  • Encryption
PrevYAML

APIs & Connections

NextRate Limit