env-and-secrets.txt
Scan this code for anything that should not be in a file I might share:
API keys, tokens, passwords, connection strings, private URLs.

<paste>

For each one found:
- Move it to an environment variable and show me the changed line.
- Give me the .env.example entry with a placeholder value.
- Tell me the .gitignore lines I need.

Then tell me what to do about any key that has already been committed.

The answer to the last question is always "rotate it". A secret that has been in a file you shared is a secret someone else has.