Environment variables
Human-readable checklist for local .env and production Wrangler secrets. AI agents should treat .env.example in the starter repo as the machine-readable list.
Application secrets
Section titled “Application secrets”| Variable | Required? | Description |
|---|---|---|
SESSION_SECRET |
Production yes | Admin session signing. Generate with openssl rand -hex 32, then wrangler secret put SESSION_SECRET. |
GUEST_TOKEN_SECRET |
Production yes | HMAC for guest order-lookup links. Same generation / inject pattern. |
PUBLIC_STRIPE_KEY |
When using Stripe | Browser publishable key (pk_…). |
STRIPE_SECRET_KEY |
When using Stripe | Server secret (sk_…) — Wrangler secret only. |
STRIPE_WEBHOOK_SECRET |
When using webhooks | Stripe webhook signing secret (whsec_…). |
PUBLIC_PAYPAL_CLIENT_ID |
When using PayPal | Browser client ID. |
PAYPAL_CLIENT_SECRET |
When using PayPal | Server secret — Wrangler secret only. |
PAYPAL_ENV |
Optional | sandbox (default) or live; must match credentials. |
RESEND_API_KEY |
When sending email | Order / contact mail; skipped if unset. |
EMAIL_FROM |
When sending email | From header, e.g. StoreCay <orders@yourdomain.com>. |
PUBLIC_INPOST_GEOWIDGET_TOKEN |
When using InPost | Browser token; enable/sandbox flags live in store.config.ts. |
Not env vars
Section titled “Not env vars”| Item | Where |
|---|---|
| Site URL, brand defaults, feature flags, CDN | store.config.ts |
| Live store profile, shipping, discounts | Admin → Settings (D1) |
D1 DB / R2 STORAGE |
wrangler.jsonc bindings |
Local .env example
Section titled “Local .env example”PUBLIC_STRIPE_KEY=STRIPE_SECRET_KEY=STRIPE_WEBHOOK_SECRET=PUBLIC_PAYPAL_CLIENT_ID=PAYPAL_CLIENT_SECRET=PAYPAL_ENV=sandboxRESEND_API_KEY=EMAIL_FROM=StoreCay <onboarding@resend.dev>SESSION_SECRET=GUEST_TOKEN_SECRET=Never commit real secrets. See Store payments for gateway setup.