← back to Secrets Manager
routes: register Kamatera full-monte/.env as a GEMINI_API_KEY destination (enrichment key switched off depleted account, TK-12090)
4efb136bdbb5dcd423526ffdc9f5ba12de9d10a1 · 2026-09-23 17:50:52 -0700 · Steve Abrams
Files touched
Diff
commit 4efb136bdbb5dcd423526ffdc9f5ba12de9d10a1
Author: Steve Abrams <steve@designerwallcoverings.com>
Date: Wed Sep 23 17:50:52 2026 -0700
routes: register Kamatera full-monte/.env as a GEMINI_API_KEY destination (enrichment key switched off depleted account, TK-12090)
---
routes.json | 134 ++++++++++++++++++++++++++++++++----------------------------
1 file changed, 71 insertions(+), 63 deletions(-)
diff --git a/routes.json b/routes.json
index d9b1b5d..23c40a9 100644
--- a/routes.json
+++ b/routes.json
@@ -11,7 +11,7 @@
]
},
"SI_API_KEY": {
- "label": "api.data.gov key (Smithsonian Open Access + other data.gov APIs) — CelebritySignatures artists harvest; account steve@designerwallcoverings.com, created 2025-08-25",
+ "label": "api.data.gov key (Smithsonian Open Access + other data.gov APIs) \u2014 CelebritySignatures artists harvest; account steve@designerwallcoverings.com, created 2025-08-25",
"verify": {
"method": "GET",
"auth": "query",
@@ -25,7 +25,7 @@
]
},
"PRINTIFY_API_TOKEN": {
- "label": "Printify personal access token — CelebritySignatures standalone wear fulfillment",
+ "label": "Printify personal access token \u2014 CelebritySignatures standalone wear fulfillment",
"verify": {
"method": "GET",
"url": "https://api.printify.com/v1/shops.json",
@@ -60,7 +60,7 @@
]
},
"REPLICATE_API_TOKEN": {
- "label": "Replicate API Token — wallco.ai SDXL gen fallback (WALLCO_COMFY_FALLBACK=replicate floor) + animate-museum-posts + interiordesignershowroom scene/hero regen",
+ "label": "Replicate API Token \u2014 wallco.ai SDXL gen fallback (WALLCO_COMFY_FALLBACK=replicate floor) + animate-museum-posts + interiordesignershowroom scene/hero regen",
"verify": {
"method": "GET",
"url": "https://api.replicate.com/v1/account",
@@ -78,7 +78,7 @@
{
"type": "project",
"path": "~/Projects/interiordesignershowroom/.env",
- "_note": "IDS hero/scene regen (TK-10402) — SCENE_PROVIDER=replicate-flux path. LOCAL only; the prod IDS .env on Kamatera is deliberately NOT routed (prod DB write stays Steve-gated)."
+ "_note": "IDS hero/scene regen (TK-10402) \u2014 SCENE_PROVIDER=replicate-flux path. LOCAL only; the prod IDS .env on Kamatera is deliberately NOT routed (prod DB write stays Steve-gated)."
},
{
"type": "project",
@@ -193,7 +193,7 @@
]
},
"STRIPE_TEST_SECRET_KEY": {
- "label": "Stripe test secret key — Charge & Explore test-mode billing only",
+ "label": "Stripe test secret key \u2014 Charge & Explore test-mode billing only",
"verify": {
"method": "GET",
"url": "https://api.stripe.com/v1/balance",
@@ -210,7 +210,7 @@
]
},
"STRIPE_TEST_WEBHOOK_SECRET": {
- "label": "Stripe test webhook signing secret — Charge & Explore",
+ "label": "Stripe test webhook signing secret \u2014 Charge & Explore",
"destinations": [
{
"type": "project",
@@ -356,7 +356,7 @@
]
},
"STRIPE_VCL_WEBHOOK_SECRET": {
- "label": "Stripe webhook signing secret — VCL endpoint we_1TUF1Y63uNmiRsMbNr1kLu52",
+ "label": "Stripe webhook signing secret \u2014 VCL endpoint we_1TUF1Y63uNmiRsMbNr1kLu52",
"destinations": [
{
"type": "project",
@@ -371,7 +371,7 @@
]
},
"STRIPE_PRICE_VCL_STARTER_MONTH": {
- "label": "Stripe Price ID — VCL Starter $49/mo",
+ "label": "Stripe Price ID \u2014 VCL Starter $49/mo",
"destinations": [
{
"type": "project",
@@ -386,7 +386,7 @@
]
},
"STRIPE_PRICE_VCL_STANDARD_MONTH": {
- "label": "Stripe Price ID — VCL Standard $99/mo",
+ "label": "Stripe Price ID \u2014 VCL Standard $99/mo",
"destinations": [
{
"type": "project",
@@ -401,7 +401,7 @@
]
},
"STRIPE_PRICE_VCL_PREMIER_MONTH": {
- "label": "Stripe Price ID — VCL Premier $199/mo",
+ "label": "Stripe Price ID \u2014 VCL Premier $199/mo",
"destinations": [
{
"type": "project",
@@ -416,7 +416,7 @@
]
},
"HEYGEN_API_KEY": {
- "label": "HeyGen API key — talking-head avatar video render (used by session-debrief skill)",
+ "label": "HeyGen API key \u2014 talking-head avatar video render (used by session-debrief skill)",
"verify": {
"method": "GET",
"url": "https://api.heygen.com/v1/voice.list",
@@ -447,7 +447,7 @@
]
},
"INFO_VENTURACLAW_COM_PASSWORD": {
- "label": "Purelymail mailbox password — info@venturaclaw.com (used by Ventura Claw Leads + the existing ventura-claw app)",
+ "label": "Purelymail mailbox password \u2014 info@venturaclaw.com (used by Ventura Claw Leads + the existing ventura-claw app)",
"destinations": [
{
"type": "project",
@@ -472,7 +472,7 @@
]
},
"INFO_NATIONALPAPERHANGERS_COM_PASSWORD": {
- "label": "Purelymail mailbox password — info@nationalpaperhangers.com",
+ "label": "Purelymail mailbox password \u2014 info@nationalpaperhangers.com",
"destinations": [
{
"type": "project",
@@ -487,7 +487,7 @@
]
},
"STRIPE_NPH_WEBHOOK_SECRET": {
- "label": "Stripe Webhook Signing Secret — NPH endpoint we_1TUDHV63uNmiRsMbRJea7EqU",
+ "label": "Stripe Webhook Signing Secret \u2014 NPH endpoint we_1TUDHV63uNmiRsMbRJea7EqU",
"destinations": [
{
"type": "project",
@@ -502,7 +502,7 @@
]
},
"STRIPE_PRICE_PRO_MONTH": {
- "label": "Stripe Price ID — NPH Pro $39/mo",
+ "label": "Stripe Price ID \u2014 NPH Pro $39/mo",
"destinations": [
{
"type": "project",
@@ -517,7 +517,7 @@
]
},
"STRIPE_PRICE_PRO_YEAR": {
- "label": "Stripe Price ID — NPH Pro $399/yr",
+ "label": "Stripe Price ID \u2014 NPH Pro $399/yr",
"destinations": [
{
"type": "project",
@@ -532,7 +532,7 @@
]
},
"STRIPE_PRICE_SIGNATURE_MONTH": {
- "label": "Stripe Price ID — NPH Signature $149/mo",
+ "label": "Stripe Price ID \u2014 NPH Signature $149/mo",
"destinations": [
{
"type": "project",
@@ -547,7 +547,7 @@
]
},
"STRIPE_PRICE_SIGNATURE_YEAR": {
- "label": "Stripe Price ID — NPH Signature $1500/yr",
+ "label": "Stripe Price ID \u2014 NPH Signature $1500/yr",
"destinations": [
{
"type": "project",
@@ -562,7 +562,7 @@
]
},
"STRIPE_PRICE_ENTERPRISE_MONTH": {
- "label": "Stripe Price ID — NPH Enterprise $399/mo",
+ "label": "Stripe Price ID \u2014 NPH Enterprise $399/mo",
"destinations": [
{
"type": "project",
@@ -787,11 +787,19 @@
{
"type": "skill",
"name": "enrich-ai-tags"
+ },
+ {
+ "type": "project",
+ "host": "45.61.58.125",
+ "user": "root",
+ "path": "/root/DW-Agents/full-monte/.env",
+ "key": "GEMINI_API_KEY"
}
- ]
+ ],
+ "_tk12090_note": "Kamatera DW image-enrichment (full-monte/.env) switched from depleted AQ.Ab8...-mvA prepaid account to this master key 2026-09-23 (TK-12090). Route registered for future rotation; NOT global-synced (surgical write, avoids touching other prod services)."
},
"GEMINI_API_KEY_DW_ENRICH": {
- "label": "Google Gemini API Key — DEDICATED to DW image-enrichment / vendor-command-center. Created 2026-06-23 by vp-security as the rotation target for the leaked orphan keys (last-4 ejMo and S2ic, never registry-managed). Pre-staged EMPTY so that the moment Steve issues a fresh key at Google AI Studio, `add GEMINI_API_KEY_DW_ENRICH <new-key>` verifies it against Gemini and fans it (remapped to the bare var GEMINI_API_KEY) to the consumers below. Distinct from the master GEMINI_API_KEY (Letsbegin/Bertha/skills) and GEMINI_API_KEY_WALLCO (k720). If Steve prefers enrichment to ride the master key instead, he can skip this alias and update GEMINI_API_KEY directly — the env-ified consumers read GEMINI_API_KEY first.",
+ "label": "Google Gemini API Key \u2014 DEDICATED to DW image-enrichment / vendor-command-center. Created 2026-06-23 by vp-security as the rotation target for the leaked orphan keys (last-4 ejMo and S2ic, never registry-managed). Pre-staged EMPTY so that the moment Steve issues a fresh key at Google AI Studio, `add GEMINI_API_KEY_DW_ENRICH <new-key>` verifies it against Gemini and fans it (remapped to the bare var GEMINI_API_KEY) to the consumers below. Distinct from the master GEMINI_API_KEY (Letsbegin/Bertha/skills) and GEMINI_API_KEY_WALLCO (k720). If Steve prefers enrichment to ride the master key instead, he can skip this alias and update GEMINI_API_KEY directly \u2014 the env-ified consumers read GEMINI_API_KEY first.",
"verify": {
"method": "GET",
"url": "https://generativelanguage.googleapis.com/v1beta/models?key={value}",
@@ -814,7 +822,7 @@
]
},
"GEMINI_API_KEY_WALLCO": {
- "label": "Google Gemini API Key — DEDICATED to wallco.ai gen pipeline (nano-banana / gemini-2.5-flash-image fallback). Distinct from the master GEMINI_API_KEY (Letsbegin/Bertha/skills). Same dedicated-alias pattern as GEMINI_API_KEY_RALPH.",
+ "label": "Google Gemini API Key \u2014 DEDICATED to wallco.ai gen pipeline (nano-banana / gemini-2.5-flash-image fallback). Distinct from the master GEMINI_API_KEY (Letsbegin/Bertha/skills). Same dedicated-alias pattern as GEMINI_API_KEY_RALPH.",
"verify": {
"method": "GET",
"url": "https://generativelanguage.googleapis.com/v1beta/models?key={value}",
@@ -1022,8 +1030,8 @@
]
},
"LINKEDIN_CLIENT_ID": {
- "label": "LinkedIn OAuth Client ID — \"For Claude - 5-6-26\" app, bound to Designer Wallcoverings Page",
- "_note": "No verify endpoint — LinkedIn requires the ID+SECRET pair to validate, and the CLI verifies one key at a time. Manual probe via POST /oauth/v2/accessToken with a fake code expects 'invalid_request: authorization code not found' = creds OK.",
+ "label": "LinkedIn OAuth Client ID \u2014 \"For Claude - 5-6-26\" app, bound to Designer Wallcoverings Page",
+ "_note": "No verify endpoint \u2014 LinkedIn requires the ID+SECRET pair to validate, and the CLI verifies one key at a time. Manual probe via POST /oauth/v2/accessToken with a fake code expects 'invalid_request: authorization code not found' = creds OK.",
"destinations": [
{
"type": "project",
@@ -1037,7 +1045,7 @@
]
},
"LINKEDIN_CLIENT_SECRET": {
- "label": "LinkedIn OAuth Client Secret — \"For Claude - 5-6-26\" app, bound to Designer Wallcoverings Page",
+ "label": "LinkedIn OAuth Client Secret \u2014 \"For Claude - 5-6-26\" app, bound to Designer Wallcoverings Page",
"destinations": [
{
"type": "project",
@@ -1051,7 +1059,7 @@
]
},
"GOOGLE_OAUTH_CLIENT_ID": {
- "label": "Google OAuth Client ID — DW Activation Calendar (shared DW Google Calendar, local :9765)",
+ "label": "Google OAuth Client ID \u2014 DW Activation Calendar (shared DW Google Calendar, local :9765)",
"destinations": [
{
"type": "project",
@@ -1060,7 +1068,7 @@
]
},
"GOOGLE_OAUTH_CLIENT_SECRET": {
- "label": "Google OAuth Client Secret — DW Activation Calendar (shared DW Google Calendar, local :9765)",
+ "label": "Google OAuth Client Secret \u2014 DW Activation Calendar (shared DW Google Calendar, local :9765)",
"destinations": [
{
"type": "project",
@@ -1069,7 +1077,7 @@
]
},
"NPH_GOOGLE_OAUTH_CLIENT_ID": {
- "label": "Google OAuth Client ID — buyer sign-in on National Paper Hangers",
+ "label": "Google OAuth Client ID \u2014 buyer sign-in on National Paper Hangers",
"destinations": [
{
"type": "project",
@@ -1083,7 +1091,7 @@
]
},
"NPH_GOOGLE_OAUTH_CLIENT_SECRET": {
- "label": "Google OAuth Client Secret — buyer sign-in on National Paper Hangers",
+ "label": "Google OAuth Client Secret \u2014 buyer sign-in on National Paper Hangers",
"destinations": [
{
"type": "project",
@@ -1341,7 +1349,7 @@
]
},
"SLACK_APP_ID": {
- "label": "Slack app \"Claude Access to Slack\" — App ID (A0BDER23QRK). Not secret but registered for completeness.",
+ "label": "Slack app \"Claude Access to Slack\" \u2014 App ID (A0BDER23QRK). Not secret but registered for completeness.",
"destinations": [
{
"type": "env_file",
@@ -1350,7 +1358,7 @@
]
},
"SLACK_CLIENT_ID": {
- "label": "Slack app Client ID — used with Client Secret in oauth.v2.access requests.",
+ "label": "Slack app Client ID \u2014 used with Client Secret in oauth.v2.access requests.",
"destinations": [
{
"type": "env_file",
@@ -1359,7 +1367,7 @@
]
},
"SLACK_CLIENT_SECRET": {
- "label": "Slack app Client Secret — OAuth token exchange (oauth.v2.access). NOT the bot token.",
+ "label": "Slack app Client Secret \u2014 OAuth token exchange (oauth.v2.access). NOT the bot token.",
"destinations": [
{
"type": "env_file",
@@ -1368,7 +1376,7 @@
]
},
"SLACK_SIGNING_SECRET": {
- "label": "Slack app Signing Secret — verifies inbound request signatures from Slack (events/interactivity).",
+ "label": "Slack app Signing Secret \u2014 verifies inbound request signatures from Slack (events/interactivity).",
"destinations": [
{
"type": "env_file",
@@ -1377,7 +1385,7 @@
]
},
"SLACK_VERIFICATION_TOKEN": {
- "label": "Slack DEPRECATED verification token — legacy request verification. Prefer SLACK_SIGNING_SECRET.",
+ "label": "Slack DEPRECATED verification token \u2014 legacy request verification. Prefer SLACK_SIGNING_SECRET.",
"destinations": [
{
"type": "env_file",
@@ -1386,7 +1394,7 @@
]
},
"SLACK_APP_TOKEN": {
- "label": "Slack app-level token (xapp-1-…) for Socket Mode — connections:write. Routes events over WebSocket. NOT the bot token (xoxb-).",
+ "label": "Slack app-level token (xapp-1-\u2026) for Socket Mode \u2014 connections:write. Routes events over WebSocket. NOT the bot token (xoxb-).",
"destinations": [
{
"type": "env_file",
@@ -1395,7 +1403,7 @@
]
},
"CENSUS_API_KEY": {
- "label": "US Census Bureau Data API key — demographics fetcher for commercialrealestate (ACS5 by ZCTA). NOTE: Census API returns 302-redirect on a valid data query so the secrets verifier cannot probe it; verify manually via an ACS5 curl.",
+ "label": "US Census Bureau Data API key \u2014 demographics fetcher for commercialrealestate (ACS5 by ZCTA). NOTE: Census API returns 302-redirect on a valid data query so the secrets verifier cannot probe it; verify manually via an ACS5 curl.",
"destinations": [
{
"type": "env_file",
@@ -1404,7 +1412,7 @@
]
},
"POSTIZ_API_KEY": {
- "label": "Postiz public API key (raw Authorization header) — DW marketing slideshow engine (post/integrations) + Postiz MCP",
+ "label": "Postiz public API key (raw Authorization header) \u2014 DW marketing slideshow engine (post/integrations) + Postiz MCP",
"destinations": [
{
"type": "project",
@@ -1413,7 +1421,7 @@
]
},
"X_API_KEY": {
- "label": "X (Twitter) API v2 — Consumer/API key (app auth). Pairs with X_API_SECRET to mint app-only bearers.",
+ "label": "X (Twitter) API v2 \u2014 Consumer/API key (app auth). Pairs with X_API_SECRET to mint app-only bearers.",
"destinations": [
{
"type": "project",
@@ -1422,7 +1430,7 @@
]
},
"X_API_SECRET": {
- "label": "X (Twitter) API v2 — Consumer/API secret. With X_API_KEY mints app-only bearer via oauth2/token.",
+ "label": "X (Twitter) API v2 \u2014 Consumer/API secret. With X_API_KEY mints app-only bearer via oauth2/token.",
"destinations": [
{
"type": "project",
@@ -1431,7 +1439,7 @@
]
},
"X_BEARER_TOKEN": {
- "label": "X (Twitter) API v2 — app-only Bearer token (use RAW/as-issued; contains %-encoded chars).",
+ "label": "X (Twitter) API v2 \u2014 app-only Bearer token (use RAW/as-issued; contains %-encoded chars).",
"verify": {
"method": "GET",
"url": "https://api.twitter.com/2/tweets?ids=20",
@@ -1492,7 +1500,7 @@
]
},
"DEEPSEEK_API_KEY": {
- "label": "DeepSeek platform API key — DeepSeek Harness CLI (dsh / @deepseek-ai/dsh); consumed via ~/.zshrc export sourced from master",
+ "label": "DeepSeek platform API key \u2014 DeepSeek Harness CLI (dsh / @deepseek-ai/dsh); consumed via ~/.zshrc export sourced from master",
"verify": {
"method": "GET",
"url": "https://api.deepseek.com/user/balance",
@@ -1501,7 +1509,7 @@
"destinations": []
},
"TYPESAFE_API_KEY": {
- "label": "TypeSafe (typesafe.ai) Jev /v1/systemone API key — jev-ultrafast browser-use fan-out; created 2026-09-22",
+ "label": "TypeSafe (typesafe.ai) Jev /v1/systemone API key \u2014 jev-ultrafast browser-use fan-out; created 2026-09-22",
"verify": {
"method": "POST",
"auth": "bearer",
@@ -1520,7 +1528,7 @@
]
},
"TEXT_MODEL_API_KEY": {
- "label": "OpenRouter API key (sk-or-v1) — jev-ultrafast TYPE_TEXT helper via openrouter.ai/api/v1 (inception/mercury-2.5); free-tier $50; created 2026-09-22",
+ "label": "OpenRouter API key (sk-or-v1) \u2014 jev-ultrafast TYPE_TEXT helper via openrouter.ai/api/v1 (inception/mercury-2.5); free-tier $50; created 2026-09-22",
"verify": {
"method": "GET",
"auth": "bearer",
@@ -1535,7 +1543,7 @@
]
},
"GEMINI_API_KEY_PATTY": {
- "label": "Google Gemini API Key — DEDICATED to Patty (Orbit/petitions/campaigns/trending routes + lib/gemini.ts). Created 2026-09-23 as the rotation target for the leaked key hardcoded in 7 Patty routes + 3 DW docs. Distinct from the master GEMINI_API_KEY.",
+ "label": "Google Gemini API Key \u2014 DEDICATED to Patty (Orbit/petitions/campaigns/trending routes + lib/gemini.ts). Created 2026-09-23 as the rotation target for the leaked key hardcoded in 7 Patty routes + 3 DW docs. Distinct from the master GEMINI_API_KEY.",
"destinations": [
{
"type": "env_file",
@@ -1545,7 +1553,7 @@
]
},
"GEMINI_API_KEY_POPPY": {
- "label": "Google Gemini API Key — DEDICATED to PoppyPetitions (lib/gemini.ts). Created 2026-09-23 as the rotation target for the leaked key hardcoded there. Distinct from the master GEMINI_API_KEY.",
+ "label": "Google Gemini API Key \u2014 DEDICATED to PoppyPetitions (lib/gemini.ts). Created 2026-09-23 as the rotation target for the leaked key hardcoded there. Distinct from the master GEMINI_API_KEY.",
"destinations": [
{
"type": "env_file",
@@ -1555,7 +1563,7 @@
]
},
"DW_SESSION_SECRET": {
- "label": "DW Central SSO HMAC session secret (TK-11776/TK-12029) — lockstep across room-setting-app, ImportNewSkufromURL, Letsbegin + issuer dw-central-next",
+ "label": "DW Central SSO HMAC session secret (TK-11776/TK-12029) \u2014 lockstep across room-setting-app, ImportNewSkufromURL, Letsbegin + issuer dw-central-next",
"destinations": [
{
"type": "env_file",
@@ -1674,7 +1682,7 @@
]
},
"GOOGLE_DRIVE_CLIENT_ID": {
- "description": "Google Drive OAuth Client ID — TSD photo-import-cli desktop app",
+ "description": "Google Drive OAuth Client ID \u2014 TSD photo-import-cli desktop app",
"destinations": [
{
"type": "env-file",
@@ -1683,7 +1691,7 @@
]
},
"GOOGLE_DRIVE_CLIENT_SECRET": {
- "description": "Google Drive OAuth Client Secret — TSD photo-import-cli",
+ "description": "Google Drive OAuth Client Secret \u2014 TSD photo-import-cli",
"destinations": [
{
"type": "env-file",
@@ -1692,7 +1700,7 @@
]
},
"GOOGLE_DRIVE_REFRESH_TOKEN": {
- "description": "Google Drive OAuth refresh token — read-only scope, owned by steveabramsdesigns@gmail.com",
+ "description": "Google Drive OAuth refresh token \u2014 read-only scope, owned by steveabramsdesigns@gmail.com",
"destinations": [
{
"type": "env-file",
@@ -1731,7 +1739,7 @@
]
},
"TMDB_API_KEY": {
- "label": "TMDB v3 API key — asseeninmovies Phase B drain (6.46M-stub queue)",
+ "label": "TMDB v3 API key \u2014 asseeninmovies Phase B drain (6.46M-stub queue)",
"verify": {
"method": "GET",
"url": "https://api.themoviedb.org/3/authentication?api_key=__VALUE__",
@@ -1743,7 +1751,7 @@
]
},
"TMDB_READ_ACCESS_TOKEN": {
- "label": "TMDB v4 read-access token (bearer) — alt to v3 api_key",
+ "label": "TMDB v4 read-access token (bearer) \u2014 alt to v3 api_key",
"verify": {
"method": "GET",
"url": "https://api.themoviedb.org/3/authentication",
@@ -1805,7 +1813,7 @@
]
},
"SHOPIFY_DRAFT_TOKEN": {
- "label": "Shopify Admin token (full access incl. write_draft_orders) — DW mural PDP custom-size checkout",
+ "label": "Shopify Admin token (full access incl. write_draft_orders) \u2014 DW mural PDP custom-size checkout",
"destinations": [
{
"type": "project",
@@ -1814,7 +1822,7 @@
]
},
"SHOPIFY_FULL_ACCESS_TOKEN": {
- "label": "Shopify Admin token — DW full Online Store pages, content, navigation, and theme access",
+ "label": "Shopify Admin token \u2014 DW full Online Store pages, content, navigation, and theme access",
"verify": {
"method": "GET",
"url": "https://designer-laboratory-sandbox.myshopify.com/admin/api/2024-10/shop.json",
@@ -1835,7 +1843,7 @@
]
},
"SHOPIFY_ADMIN_ACCESS_TOKEN": {
- "label": "Shopify Admin API access token (ACCESS-name alias of SHOPIFY_ADMIN_TOKEN) — DW live store; now MANAGED to stop TK-10930 drift",
+ "label": "Shopify Admin API access token (ACCESS-name alias of SHOPIFY_ADMIN_TOKEN) \u2014 DW live store; now MANAGED to stop TK-10930 drift",
"verify": {
"method": "GET",
"url": "https://designer-laboratory-sandbox.myshopify.com/admin/api/2024-10/shop.json",
@@ -2052,13 +2060,13 @@
]
},
"DATAFORSEO_API_KEY": {
- "label": "DataForSEO API key (base64 of login:api-password) — OpenSEO self-hosted backend for keyword/SERP/backlink/domain tools. Login steve@designerwallcoverings.com.",
+ "label": "DataForSEO API key (base64 of login:api-password) \u2014 OpenSEO self-hosted backend for keyword/SERP/backlink/domain tools. Login steve@designerwallcoverings.com.",
"destinations": [
"/Users/macstudio3/Projects/open-seo/.env.local"
]
},
"OSBORNE_USERNAME": {
- "label": "Osborne & Little trade portal (tradenew.osborneandlittle.com) login — also used for Matthew Williamson (O&L-distributed) US pricing",
+ "label": "Osborne & Little trade portal (tradenew.osborneandlittle.com) login \u2014 also used for Matthew Williamson (O&L-distributed) US pricing",
"destinations": [
{
"type": "skill",
@@ -2082,7 +2090,7 @@
]
},
"SHOPIFY_DW_APP_CLIENT_SECRET": {
- "label": "Shopify DW app API secret (OAuth + webhook HMAC) — consumed by shopify-oauth-catcher which reads this master .env directly (no fan-out). Rotated 2026-08-10.",
+ "label": "Shopify DW app API secret (OAuth + webhook HMAC) \u2014 consumed by shopify-oauth-catcher which reads this master .env directly (no fan-out). Rotated 2026-08-10.",
"destinations": [
{
"type": "master-only",
@@ -2106,7 +2114,7 @@
]
},
"SHOPIFY_SIGNUP_APP_CLIENT_SECRET": {
- "label": "Shopify dw-signup-fulfillment installed app secret — OAuth and webhook HMAC verification.",
+ "label": "Shopify dw-signup-fulfillment installed app secret \u2014 OAuth and webhook HMAC verification.",
"destinations": [
{
"type": "project",
@@ -2121,7 +2129,7 @@
]
},
"SHOPIFY_FREE_SAMPLES_APP_CLIENT_SECRET": {
- "label": "Shopify DW Free Samples app secret — orders/paid webhook HMAC verification; sourced directly from Shopify CLI app env.",
+ "label": "Shopify DW Free Samples app secret \u2014 orders/paid webhook HMAC verification; sourced directly from Shopify CLI app env.",
"destinations": [
{
"type": "project",
@@ -2158,7 +2166,7 @@
]
},
"SLACK_BOT_TOKEN": {
- "label": "Slack bot token (dw_reports_bot @ Designerwallcoverings, bot_id B0BC0EB3GPP) — slack MCP server",
+ "label": "Slack bot token (dw_reports_bot @ Designerwallcoverings, bot_id B0BC0EB3GPP) \u2014 slack MCP server",
"destinations": [
{
"type": "mcp",
@@ -2194,7 +2202,7 @@
]
},
"INNOVATIONS_LOGIN_URL": {
- "label": "Innovations USA trade-portal login URL — VERIFIED 2026-09-11: https://www.innovationsusa.com/login returns 200 with a password field, 'Sign In' and 'Trade' copy. NOTE the page carries reCAPTCHA, so a plain curl/fetch login will NOT work — the pull must go through the browserbase + 2captcha path. (/customer/account/login/ and /customer/account/ both 404, so this is NOT stock Magento routing despite the Magento stack.) TK-11041.",
+ "label": "Innovations USA trade-portal login URL \u2014 VERIFIED 2026-09-11: https://www.innovationsusa.com/login returns 200 with a password field, 'Sign In' and 'Trade' copy. NOTE the page carries reCAPTCHA, so a plain curl/fetch login will NOT work \u2014 the pull must go through the browserbase + 2captcha path. (/customer/account/login/ and /customer/account/ both 404, so this is NOT stock Magento routing despite the Magento stack.) TK-11041.",
"destinations": [
{
"type": "env_file",
@@ -2217,7 +2225,7 @@
"url": "https://api.stripe.com/v1/account",
"auth": "basic-sk"
},
- "note": "App-scoped: professional-directory only. Generic var name — do NOT register a second app's Stripe key here without scoping (would misroute). Verify hits Stripe /v1/account (basic-sk); a sk_live_ key returns 200 with the live account."
+ "note": "App-scoped: professional-directory only. Generic var name \u2014 do NOT register a second app's Stripe key here without scoping (would misroute). Verify hits Stripe /v1/account (basic-sk); a sk_live_ key returns 200 with the live account."
},
"/Users/macstudio3/Projects/professional-directory/.env",
"/Users/macstudio3/Projects/site-factory/.env",
@@ -2241,4 +2249,4 @@
"/Users/macstudio3/Projects/all-designerwallcoverings/.env",
"/Users/macstudio3/.claude/skills/browserbase/.env"
]
-}
+}
\ No newline at end of file
← b5cdf49 auto-data-snapshot: 2026-09-23T12:42:16 (1 data files) — reg
·
back to Secrets Manager
·
auto-data-snapshot: 2026-09-24T14:21:31 (1 data files) — reg 4464cbf →