Prompt
What should I use to keep API configs out of app code?
Latest observation
Oct 5, 2026
OpenAI APIWeb search: off
Use environment variables or a separate config management system—not hardcoded values in app code.
Common options:
- Environment variables: Best for API keys, URLs, and secrets
.envfiles: Good for local development, but don’t commit them to git- Config files outside source control: e.g.
config.yaml,settings.jsonloaded at runtime - Secret managers: Best for production
- AWS Secrets Manager
- Azure Key Vault
- Google Secret Manager
- HashiCorp Vault
Good practice:
- Keep secrets out of code and repos
- Use different configs for dev/test/prod
- Rotate keys regularly
- Load configs at startup, not embedded in logic
If you want, I can show the best setup for your stack (Node, Python, Java, etc.).