Reference
Environment Bindings Reference
Reference list for partners-api Worker bindings and what developers must know before using them.
First created Last updated
End-to-end developer runbook
- Step 1 - Confirm the API area: Identify the product area, route module, endpoint path, and consumer before writing or calling code.
- Step 2 - Read the endpoint contract: Check method, auth, parameters, response, errors, side effects, and related docs.
- Step 3 - Prepare authentication and input: Use the right session, bearer token, webhook secret, or internal header. Validate body and query data before sending it.
- Step 4 - Make the request: Call the endpoint from the correct origin and environment. Keep credentials and secrets out of logs.
- Step 5 - Verify response, side effects, and records: Confirm status code, response shape, database records, external side effects, and audit evidence.
- Step 6 - Add tests, docs, and handoff notes: Update route inventory, consumer notes, and certification checks before depending on the change.
Binding checklist
- Action 1 - Confirm binding exists in
Env: Source of truth ispartners-api/src/index.ts. - Action 2 - Confirm local value exists: Development cannot rely on production-only secrets.
- Action 3 - Confirm deployment value exists: Wrangler and Cloudflare environments must have the binding.
- Action 4 - Confirm routes using it are documented: Link each binding to route families and workflows.
Major binding groups
| Group | Examples | Risk |
|---|---|---|
| Supabase | SUPABASE_URL, keys, JWT secret | database auth and service access |
| Origins | ALLOWED_ORIGIN, dashboard, site, rego URLs | credentialed CORS and links |
| CMS/media | Sanity and CMS bindings | uploads and content management |
| Mail/hooks | GAS mail and Auth hook secrets | outbound email and account lifecycle |
| Social | Discord, Telegram, social-link state | identity linking and role sync |
| Finance/wallet | Google Wallet bindings | passes and attendee entitlements |
| Internal | cron, test-control, suppression | automation and certification safety |
| LAN releases | GitHub owner, repo, token | release download proxy |