Why I'm Dealing With This Again
Leading a small team, the scariest thing isn't technical challenges—it's "nobody knows where the keys are." Here's a scenario from last week: the AI API in the test environment suddenly started returning 401 errors. After a long troubleshooting session, we found that a team member had hardcoded a Key from their own computer into the code. That Key had been rotated the week before, so the test environment was the first to break.
This isn't an isolated case. The most common state for indie developers and small teams is: one Key for development, another for testing, and the production Key living in some early member's notes. Nobody is acting maliciously—there's just no rule in place.
This article is about establishing that rule: manage API Keys across environments uniformly with environment variables, making the process traceable, collaboration frictionless, and risks controllable.
First, Think It Through: What Does a Manager Actually Need
From a management perspective, Key management must satisfy three things:
- Reproducible process—a new member can get the code running on day one without having to "go ask Bob."
- Conflict-free collaboration—development, testing, and production configs stay out of each other's way, and changes are traceable.
- Controllable risk—when a Key leaks, you can quickly locate it, quickly rotate it, and minimize the blast radius.
Environment variables are the lowest-cost way to achieve all three. They require no additional infrastructure, introduce no new operational burden, and are naturally tied to the environment—which is exactly the core of "multi-environment" setups.
Step 1: Register on ThisToken.AI and Get an API Key
Using ThisToken.AI as an example (the process is similar on other platforms):
- Visit the ThisToken.AI website and register an account. Use a team shared email for the main account rather than a personal one—this is the first line of risk control at the management level, preventing the account from slipping out of control as people come and go.
- After logging in, go to the console and create a Key on the API Key management page.
- Key action: create a separate Key for each environment. For example,
dev-team-alpha,staging-team-alpha,prod-team-alpha. Include the environment in the name, so you can tell at a glance who is calling and in which environment from the logs and billing. For pricing, always refer to the official pricing page—don't trust secondhand information. - Copy and save the Key immediately after creation—most platforms only show it once.
Step 2: Design the Directory Structure and Configuration Conventions
Recommended team conventions (small enough that you don't need documentation tools—a single file suffices):
project/
├── .env.example # Committed to Git, contains variable names only, no values
├── .env # Actually effective locally, excluded via .gitignore
├── .env.staging # For the test environment, distributed via secure channels, never committed
└── .gitignore # Must include .env*.env.example is the team's "configuration contract":
# .env.example
THISTOKEN_API_KEY=your-key-here
THISTOKEN_BASE_URL=https://api.thistoken.ai/v1The onboarding path for new members thus becomes three steps: clone the repo, copy .env.example to .env, and get a Key from the administrator to fill in. No need to ask anyone, and no chance of mistyping a variable name.
A habit for managers: spend two minutes every week running git grep to check whether anyone has written a real Key into the code. Once a Key enters Git history, deleting the commit doesn't count as the end of the leak.
Step 3: Get Your First Piece of Code Running
Once the environment variables are configured, the first piece of verification code should be simple enough to need no explanation. Here's a Python example:
import os
from openai import OpenAI
# 从环境变量读取,代码中不出现任何明文 Key
client = OpenAI(
api_key=os.environ["THISTOKEN_API_KEY"],
base_url="https://api.thistoken.ai/v1",
)
response = client.chat.completions.create(
model="gpt-4o-mini",
messages=[
{"role": "system", "content": "你是一个简洁的助手。"},
{"role": "user", "content": "用一句话解释什么是环境变量。"},
],
)
print(response.choices[0].message.content)Set the environment variable before running:
# Linux / macOS
export THISTOKEN_API_KEY="sk-你的key"
# Windows PowerShell
$env:THISTOKEN_API_KEY="sk-你的key"Note two details: use os.environ["THISTOKEN_API_KEY"] with square brackets rather than .get()—if the Key is missing, it fails immediately, which is better than silently sending empty-value requests for hours; and define base_url as a variable or environment variable, so that switching environments in the future only requires changing configuration, not code.
If you use a .env file with python-dotenv, just add from dotenv import load_dotenv; load_dotenv() at the top of your script—and be careful not to commit .env to the repository.
The JavaScript version works the same way: read the value via process.env.THISTOKEN_API_KEY and point baseURL to https://api.thistoken.ai/v1.
Risk Control: Three Rules You Must Establish
Rule one: be able to rotate within 60 seconds of a leak. Because each environment has its own Key, a leaked production Key only requires revoking and reissuing that one Key in the console—development and testing are completely unaffected. This is the "minimal blast radius" mentioned at the beginning.
Rule two: distribute Keys through secure channels. Never send Keys in plaintext in group chats. Use a password manager's sharing feature, or one-time encrypted sharing links.
Rule three: audit regularly. Check the Key list in the console once a month, and revoke the Keys of departing members that same day. It takes no time, but you're the only one who remembers to do it—and that's precisely a manager's responsibility.
Final Thoughts
Multi-environment Key management isn't technical showboating—it's about giving your team a reliable process at minimal cost. From registering on ThisToken.AI, creating Keys per environment, to getting your first piece of code running with environment variables, the whole thing takes less than an hour, and what you get in return is zero friction every time a new environment or new member comes on board.
If you don't have an account yet, you can start by registering here: https://api.thistoken.ai/register
---
Every example in this post runs with a single API key — get yours at https://api.thistoken.ai/register and start in minutes.
Token.AI を試してみませんか?
プロジェクトレベルの API Key を作成し、コンソールでチャネルを有効にして、ルーティング、予算、監査ログを設定しましょう。
注册 ThisToken.AI 并获取 API Key