Store credentials securely

You now hold: api_key, api_secret, and soon a daily access_token. Leaking any of these lets someone place orders on your account with your money. Treat them like a bank password.

.env file

# .env  (never commit this file)
KITE_API_KEY=your_api_key_here
KITE_API_SECRET=your_api_secret_here
KITE_ACCESS_TOKEN=

config.py:

import os
from dotenv import load_dotenv

load_dotenv()

API_KEY = os.environ["KITE_API_KEY"]
API_SECRET = os.environ["KITE_API_SECRET"]
ACCESS_TOKEN = os.environ.get("KITE_ACCESS_TOKEN") or None

Using os.environ["KITE_API_KEY"] (not .get) means the process fails loudly at startup if the key is missing, instead of failing mysteriously later with an auth error.

Rules, non-negotiable

  1. .env is in .gitignore — verify with git check-ignore -v .env.
  2. Never print secrets to logs. If you log request/response payloads for debugging, redact api_secret and access_token before writing.
  3. Never paste secrets into a chat tool, ticket, or AI assistant when asking for help — rotate them immediately if you ever do.
  4. If you deploy to a VPS (chapter 93), set secrets as environment variables in the service manager (e.g. systemd EnvironmentFile=), not baked into a Docker image layer or committed config.
  5. Rotate api_secret from the developer console if you ever suspect exposure — this invalidates old sessions immediately.

Better than .env for production

Once you're past learning and running unattended capital, move to an OS keyring (keyring package) or a secrets manager (age-encrypted file, Vault, AWS Secrets Manager). .env is fine for development; for a bot running 24/7 on a VPS holding your only copy of the access token, prefer a mechanism where the file at rest is encrypted.

Next: 007 — Generate the login URL, manual login flow