A `NEXT_PUBLIC_` OpenAI key drained $8,000 in 4 hours. Root cause: `NEXT_PUBLIC_` inlined the key into client JS. The fix: Keep secrets server-only; never prefix them `NEXT_PUBLIC_`.
A production war story from the TheCodeForge Next.js series — the incident, why it happened, and the exact fix.
⏳ Timestamps:
0:00 - Cold open: $8,000 in 4 hours
0:10 - Version Compatibility: Next.js 14+
0:49 - Production Caveat: Build-Time vs Runtime
1:13 - Intro
1:22 - What Is Environment Variables Config?
1:43 - What NEXT_PUBLIC_ Actually Does
2:16 - Server-Only Secrets Pattern
2:50 - Runtime Validation with Zod
3:20 - API Key Security Measures
3:49 - .env File Resolution Order
4:19 - NEXT_PUBLIC_ Best Practices
4:53 - $8,000 in 4 hours
5:20 - NEXT_PUBLIC_ for secrets
5:29 - The Fix
5:52 - ⚠ Gotcha: Using NEXT_PUBLIC_ for API keys
6:05 - ⚠ Gotcha: Assuming .env.local works in production
6:19 - ⚠ Gotcha: No Zod validation at startup
6:30 - Debugging Guide
6:45 - Interview Questions
7:09 - FAQ
7:33 - Key Takeaways
7:48 - Next up
8:11 - Wrap-up
👉 Full article + code: https://thecodeforge.io/javascript/ne...
⏭ Next up: Testing Next.js Applications: Unit, Integration, and E2E Testing
#nextjs #javascript