AuthFlow
Sign in

Environment variables

Two, and both are server-only. Put them in .env.local during development and in your host’s environment settings in production.

Server-only — never exposed to the browser

AUTHFLOW_SECRET_KEY=af_live_k1a2b3c4_REPLACE_WITH_YOUR_OWN

Authenticates your app to AuthFlow. Read on the server by the proxy route and by currentUser(). Shown once, when you create an app.

AUTHFLOW_API_URL=https://your-api.onrender.com

Where the AuthFlow API lives — the screen that shows your key fills in the right value. Not a secret, but server-only anyway: the browser only ever talks to your own proxy route.

Public — exposed to every visitor

None. The browser only talks to your own proxy route, at a relative path, so there is nothing it needs to be told.