Skip to content

Environment variables

Human-readable checklist for local .env and production Wrangler secrets. AI agents should treat .env.example in the starter repo as the machine-readable list.

Variable Required? Description
SESSION_SECRET Production yes Admin session signing. Generate with openssl rand -hex 32, then wrangler secret put SESSION_SECRET.
GUEST_TOKEN_SECRET Production yes HMAC for guest order-lookup links. Same generation / inject pattern.
PUBLIC_STRIPE_KEY When using Stripe Browser publishable key (pk_…).
STRIPE_SECRET_KEY When using Stripe Server secret (sk_…) — Wrangler secret only.
STRIPE_WEBHOOK_SECRET When using webhooks Stripe webhook signing secret (whsec_…).
PUBLIC_PAYPAL_CLIENT_ID When using PayPal Browser client ID.
PAYPAL_CLIENT_SECRET When using PayPal Server secret — Wrangler secret only.
PAYPAL_ENV Optional sandbox (default) or live; must match credentials.
RESEND_API_KEY When sending email Order / contact mail; skipped if unset.
EMAIL_FROM When sending email From header, e.g. StoreCay <orders@yourdomain.com>.
PUBLIC_INPOST_GEOWIDGET_TOKEN When using InPost Browser token; enable/sandbox flags live in store.config.ts.
Item Where
Site URL, brand defaults, feature flags, CDN store.config.ts
Live store profile, shipping, discounts Admin → Settings (D1)
D1 DB / R2 STORAGE wrangler.jsonc bindings
PUBLIC_STRIPE_KEY=
STRIPE_SECRET_KEY=
STRIPE_WEBHOOK_SECRET=
PUBLIC_PAYPAL_CLIENT_ID=
PAYPAL_CLIENT_SECRET=
PAYPAL_ENV=sandbox
RESEND_API_KEY=
EMAIL_FROM=StoreCay <onboarding@resend.dev>
SESSION_SECRET=
GUEST_TOKEN_SECRET=

Never commit real secrets. See Store payments for gateway setup.