I have an Amplify app (frontend only) serving my Next.js app. In side my /api/ folder I have a file that creates the stripe session to redirect the user to Stripe in order to pay.
In order to create the stripe session, I need to pass to stripe my STRIPE_SECRET_KEY, however, if I call it like this:
const stripe = require('stripe')(process.env.STRIPE_SECRET_KEY)
the API key si not available in my deployed app.
My question is, what is the best practice to have this API key available in my production build?