Foundations
Environments and Bindings
Worker bindings, secrets, local development variables, and external systems used by partners-api.
First created Last updated
End-to-end developer runbook
- Step 1 - Confirm the API area: Identify the product area, route module, endpoint path, and consumer before writing or calling code.
- Step 2 - Read the endpoint contract: Check method, auth, parameters, response, errors, side effects, and related docs.
- Step 3 - Prepare authentication and input: Use the right session, bearer token, webhook secret, or internal header. Validate body and query data before sending it.
- Step 4 - Make the request: Call the endpoint from the correct origin and environment. Keep credentials and secrets out of logs.
- Step 5 - Verify response, side effects, and records: Confirm status code, response shape, database records, external side effects, and audit evidence.
- Step 6 - Add tests, docs, and handoff notes: Update route inventory, consumer notes, and certification checks before depending on the change.
Binding groups
- Action 1 - Core database:
SUPABASE_URL,SUPABASE_ANON_KEY,SUPABASE_SECRET_KEY,SUPABASE_SERVICE_ROLE_KEY, andSUPABASE_JWT_SECRET. - Action 2 - Origins and apps:
ALLOWED_ORIGIN,DASHBOARD_URL,SITE_URL, andREGO_URL. - Action 3 - CMS and media:
CMS_GATE_SECRET,CMS_JWT_SECRET,CMS_TOKENS,SANITY_MEDIA_PROJECT_ID,SANITY_MEDIA_DATASET,SANITY_MEDIA_TOKEN,SANITY_PROJECT_ID, andSANITY_API_TOKEN. - Action 4 - Mail and hooks:
CONTACT_TO_EMAIL,CONTACT_FROM_EMAIL,FPH_SUPPORT_EMAIL,GAS_EMAIL_WEBHOOK_URL,GAS_EMAIL_WEBHOOK_SECRET, andSUPABASE_AUTH_HOOK_SECRET. - Action 5 - Internal controls:
CRON_SECRET,TEST_CONTROL_SECRET,STRESS_TEST_SUPPRESS_SIDE_EFFECTS. - Action 6 - Integrations: Google Wallet, Discord, Telegram, social-link state, partner DB config encryption, and LAN release GitHub bindings.