Hikari by CoreMVP

Environment variables

Find Hikari’s seven settings and keep private values on the server.

Use ignored .env.local locally and your Vercel deployment environment when hosted. ./coremvp env list reports whether each setting is present without displaying values. .env.example defines the names; never commit actual credentials.

VariableSource and purpose
APP_URLApplication origin used for Auth, billing returns, and canonical URLs
NEXT_PUBLIC_SUPABASE_URLSelected Supabase project’s API URL
NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEYSelected Supabase project’s public client key
DATABASE_URLServer Postgres connection; use TLS and transaction pooling when hosted
STRIPE_SECRET_KEYServer key for the selected Stripe account
STRIPE_PRICE_IDThe one approved recurring price
STRIPE_WEBHOOK_SECRETSigning secret for this environment’s webhook endpoint

Local values

Start local Supabase, then run ./coremvp env sync to derive the Supabase and database settings. Existing Stripe values are preserved. The application origin is http://localhost:3000; the local E2E requires that exact origin. Keep custom APP_URL changes deliberate, because Auth callbacks and return destinations use it.

Authentication can run before Stripe is configured. Checkout, Portal, and subscriber-access checks require the billing settings. Connect subscriptions for the local listener and test price.

Hosted values

Use your final HTTPS origin with no path, query, or embedded credentials as APP_URL. Local loopback HTTP is supported for development; hosted origins require HTTPS. The database uses Supabase’s transaction pooler with prepare: false and TLS.

Only the two NEXT_PUBLIC_SUPABASE_* values may reach the browser. Never prefix a database URL, Stripe secret, signing secret, or privileged provider credential with NEXT_PUBLIC_.

The local Stripe listener and hosted Stripe endpoint each have their own signing secret. Do not interchange them. Follow Deploy to Vercel to place each value in the correct provider environment.

On this page