Secrets Setup (Supabase)
Keep all provider secrets in Supabase project secrets (Edge Functions) rather than in the frontend. Example command (replace values):
supabase secrets set \
RESEND_API_KEY=... RESEND_FROM="Alhuda Travels <no-reply@alhuda.co.in>" \
MAILJET_API_KEY=... MAILJET_SECRET=... MAIL_FROM="Alhuda Travels <no-reply@alhuda.co.in>" \
WHATSAPP_ACCESS_TOKEN=... WHATSAPP_PHONE_NUMBER_ID=... WHATSAPP_VERIFY_TOKEN=... \
WHATSAPP_DEFAULT_COUNTRY_CODE=91 WHATSAPP_OTP_TEMPLATE_NAME=... WHATSAPP_TEMPLATE_LANGUAGE=en_US \
COMMUNICATION_DISPATCH_KEY=... \
CLOUDINARY_URL=... \
B2_ENDPOINT=... B2_BUCKET=... B2_ACCESS_KEY_ID=... B2_SECRET_ACCESS_KEY=... \
IDRIVEE2_ENDPOINT=... IDRIVEE2_REGION=... IDRIVEE2_BUCKET=... IDRIVEE2_ACCESS_KEY_ID=... IDRIVEE2_SECRET_ACCESS_KEY=... \
GOOGLE_DRIVE_PROJECT_ID=... GOOGLE_DRIVE_CLIENT_EMAIL=... GOOGLE_DRIVE_PRIVATE_KEY="..." \
TURNSTILE_SECRET_KEY=... \
AIRLABS_API_KEY=...
AIRLABS_API_KEY is the AirLabs flight-schedule key, read only by the flight-lookup function. It used to be the browser variable VITE_AIRLABS_API_KEY; that variable is gone and must not be set (PLT-015).
For local builds, use .env.local (ignored) and copy from env.example only if you need non-sensitive values (anon keys, public site keys). Do not store secrets in the frontend.***
WhatsApp notes:
WHATSAPP_ACCESS_TOKENshould be a Meta system-user token withwhatsapp_business_messaging.WHATSAPP_PHONE_NUMBER_IDis the sender number ID used by Cloud API.WHATSAPP_VERIFY_TOKENis the custom token Meta sends back during webhook verification.WHATSAPP_OTP_TEMPLATE_NAMEis the approved Meta authentication template (copy-code button) used for every code the system sends — the customer and partner password reset code (ACC-069) and the finance PIN reset code. Meta refuses a code sent any other way. Leave it unset until the template is approved; the reset page then says WhatsApp codes are not switched on. See docs/operations/whatsapp-cloud-api.md.COMMUNICATION_DISPATCH_KEYcan be used by your cron/scheduler to call thecommunications-dispatcherfunction securely. If omitted, use the Supabase service role key as the authorization bearer token for the dispatcher.