Environment variables
Two, and both are server-only. Put them in .env.local during development and in your host’s environment settings in production.
Server-only — never exposed to the browser
AUTHFLOW_SECRET_KEY=af_live_k1a2b3c4_REPLACE_WITH_YOUR_OWNAuthenticates your app to AuthFlow. Read on the server by the proxy route and by currentUser(). Shown once, when you create an app.
AUTHFLOW_API_URL=https://your-api.onrender.comWhere the AuthFlow API lives — the screen that shows your key fills in the right value. Not a secret, but server-only anyway: the browser only ever talks to your own proxy route.
Public — exposed to every visitor
None. The browser only talks to your own proxy route, at a relative path, so there is nothing it needs to be told.
NEXT_PUBLIC_