What’s in Settings
API Keys
Create, scope, and rotate keys that let external apps, scripts, and tools call your API.
Environment variables
Store configuration values your app reads at runtime instead of hard-coding them.
Network
Control which origins can call your API (CORS) and how traffic is rate-limited.
Settings and environments
Settings are tied to your environments. Before you change anything, check which environment is active in the environment switcher.- API keys belong to one environment. A key created in staging does not work in production.
- Environment variables can be scoped per environment, so production-only secrets stay out of development.
- Network settings are project-wide defaults, scoped per environment.
Related pages
- Role-Based Access — an API key gets its permissions from the roles you assign to it.
- Custom APIs — override CORS and rate limits for a single route.
- Integrations — the better place for third-party credentials like Stripe or SendGrid keys.
FAQ
Can I use the same API key in every environment?
Can I use the same API key in every environment?
No. Each environment has its own set of keys. Create a separate key in each environment that needs one.
Should I put integration credentials in environment variables?
Should I put integration credentials in environment variables?
Use Integrations for credentials like Stripe or SendGrid keys. Integrations handle rotation and isolation better than raw environment variables.
Can I set different CORS rules for one endpoint?
Can I set different CORS rules for one endpoint?
Yes. Network settings are the defaults for the whole project. To change the rules for one route, configure it in Custom APIs.