Vovy creates a .env.local file with the right variable names for your framework, checks .gitignore so keys never hit GitHub, and adds a .env.example.
Set up a .env file for my Supabase and OpenAI keys and keep it out of git
How it works
- Detect your framework: Vovy reads package.json to see if you use Vite, Next.js or Expo, since each needs a different prefix like VITE_, NEXT_PUBLIC_ or EXPO_PUBLIC_.
- Collect keys from dashboards: Vovy opens Supabase Project Settings, API Keys and your OpenAI API keys page in your signed-in browser, and copies only what the app needs.
- Write .env.local: Vovy creates the file and labels which keys are public, safe in the browser, and which are secret and must stay on the server.
- Lock it out of git: Vovy checks .gitignore covers .env files and runs git status to prove the file is not staged for a commit.
- Add a .env.example: Vovy writes a copy with blank values for teammates, restarts your dev server, and shows a card of every variable and where it came from.
What you provide
- Access to your Supabase and OpenAI dashboards
- Your project folder
What you get
- A working .env.local
- Public vs secret keys labeled
- .env files ignored by git
- A shareable .env.example
FAQ
Is a key with VITE_ or NEXT_PUBLIC_ in front secret?
No. Those prefixes deliberately ship the value to the browser, where anyone can read it. Never put an OpenAI key or Supabase service_role key behind one.
Why is my new variable undefined?
Most dev servers only read .env files at startup. Restart npm run dev after editing, and check the prefix matches your framework.
Does .env.local go to Vercel?
No, it stays on your Mac. You add the same variables in your host's environment variable settings for production.
Related tasks
All tasks