Level 1 · Lesson 3
Lock the key in the safe
Level 1 · Lesson 3Store the API Ninjas key as an encrypted variable before any code uses it, so it never sits in a file, a commit or the browser.
Behind, or starting here? Download the code as it should be before this lesson.
Lesson 4 calls API Ninjas, and every call needs your key. The key goes in first, before there is any code that could tempt you to paste it in. This lesson changes no files.
Step 1: Put the key in the safe
Locked until the step before it is done.
Runs in the Atlassian cloud · Back of house
Environment variable · the safe
An environment variable is a named value stored with the app, per environment. Functions read it as process.env.NAME. With --encrypt, the value is stored encrypted and forge variables list never shows it again. UI code in the browser cannot read variables at all, which is one more reason the supplier call happens in a function.
In the kitchen Account numbers and door codes go in the safe, never in the playbook.
process.env.It opens the safe for the account number.In the app folder, run:
forge variables set --encrypt API_NINJAS_KEYThe CLI asks for the value and hides what you type. Paste your API Ninjas key and press Enter. Because the value is never part of the command, it stays out of your shell history too.
Stuck? I set or changed a variable
Next step: next
Step 2: Check it is there, and hidden
Locked until the step before it is done.
forge variables listYou should see API_NINJAS_KEY with a tick under Encrypted? and no value. Nobody, including you, can read it back from here. If you ever need to change it, set it again.
Next step: next
Step 3: Deploy so functions can read it
Locked until the step before it is done.
The CLI reminds you of this itself: a new or changed variable reaches functions only with the next deploy.
forge deployStuck? I set or changed a variable
Next step: next
Step 4: Optional: give the tunnel the key too
Locked until the step before it is done.
While forge tunnel runs, your laptop runs the code, and it reads variables from your own shell, not from the safe. Forge looks for the name with FORGE_USER_VAR_ in front.
In bash or zsh, this asks for the key without showing it and keeps it for this terminal only:
read -s FORGE_USER_VAR_API_NINJAS_KEY && export FORGE_USER_VAR_API_NINJAS_KEYStart forge tunnel from the same terminal. Skip this step if you will only test the supplier call after a deploy.
Next step: next