feat: bind SERVER_API_TOKEN from Secrets Store - #16
Merged
colinmcdonald22 merged 4 commits intoSep 13, 2026
Merged
Conversation
Add secrets_store_secrets bindings for the production and development environments so the Worker receives the server API key from Cloudflare Secrets Store instead of a plain Worker secret.
Secrets Store bindings expose the value via an async get() rather than a plain string, so the header was going to be sent as [object Object]. Resolve the token at request time, calling get() when the binding is present and falling back to the plain string from .env for local dev. The resolved value is cached per isolate; failed lookups are not cached.
Use event.platform.env.SERVER_API_TOKEN.get() directly instead of sniffing the shape of the dynamic env value and caching it. Falls back to the .env string when the binding is absent (local vite dev). Adds a minimal App.Platform type for the binding.
The platform proxy used by vite build/dev exposes SERVER_API_TOKEN as a string from the process env, so calling get() on it broke prerendering in CI. Only call get() when the value is the Secrets Store binding.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
secrets_store_secretsbindings forSERVER_API_TOKENto theproductionanddevelopmentenvironments inwrangler.jsonc, sourcing the server API key (skycrypt-server-api-key) from Cloudflare Secrets Store instead of a plain Worker secret.Secrets Store bindings expose the value via an async
get()rather than a plain string, socustom-instance.tsnow reads the token straight from the Worker binding:In local
vite dev, CI prerender, and anywhere else the platform proxy is used, the value is a plain string from the process env or.env, soget()is only called on the real binding.App.Platforminapp.d.tstypes it asstring | { get(): Promise<string> }.Also ran
oxfmtonwrangler.jsoncsopnpm lintpasses.Verification
svelte-check: 0 errorseslinton changed files: cleanpnpm build(including prerender) passes locallyX-API-Tokenarrives at the backend.