# Development Setup ## Secrets Runtime secrets are read from the local process environment. Copy `.env.example` to `.env` for local notes if needed, but do not commit real credentials. The application must not hard-code API keys or authorization headers in source files. Current environment keys: - `MUSIC_ASSISTANT_OPENAI_API_KEY` Provider integrations are intentionally protocol-only in the repository foundation phase.