Store credentials securely
You now hold: api_key, api_secret, and soon a daily access_token. Leaking any of these lets someone place orders on your account with your money. Treat them like a bank password.
.env file
# .env (never commit this file)
KITE_API_KEY=your_api_key_here
KITE_API_SECRET=your_api_secret_here
KITE_ACCESS_TOKEN=
config.py:
import os
from dotenv import load_dotenv
load_dotenv()
API_KEY = os.environ["KITE_API_KEY"]
API_SECRET = os.environ["KITE_API_SECRET"]
ACCESS_TOKEN = os.environ.get("KITE_ACCESS_TOKEN") or None
Using os.environ["KITE_API_KEY"] (not .get) means the process fails loudly at startup if the key is missing, instead of failing mysteriously later with an auth error.
Rules, non-negotiable
.envis in.gitignore— verify withgit check-ignore -v .env.- Never print secrets to logs. If you log request/response payloads for debugging, redact
api_secretandaccess_tokenbefore writing. - Never paste secrets into a chat tool, ticket, or AI assistant when asking for help — rotate them immediately if you ever do.
- If you deploy to a VPS (chapter 93), set secrets as environment variables in the service manager (e.g. systemd
EnvironmentFile=), not baked into a Docker image layer or committed config. - Rotate
api_secretfrom the developer console if you ever suspect exposure — this invalidates old sessions immediately.
Better than .env for production
Once you're past learning and running unattended capital, move to an OS keyring (keyring package) or a secrets manager (age-encrypted file, Vault, AWS Secrets Manager). .env is fine for development; for a bot running 24/7 on a VPS holding your only copy of the access token, prefer a mechanism where the file at rest is encrypted.