# How to Configure APIMart API Keys for Production‑Ready Image Generation

> Secure your production image generation by configuring APIMart API keys. Learn how to set the APIMART_API_KEY environment variable to prevent unauthorized requests and ensure smooth operation.

- Repository: [苍何/awesome-gpt-image-2](https://github.com/freestylefly/awesome-gpt-image-2)
- Tags: how-to-guide
- Published: 2026-09-11

---

**Store your APIMart API key in the `APIMART_API_KEY` environment variable; the application detects it via `getApimartConfig()` in [`api/_lib/apimart.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/api/_lib/apimart.js) and returns `SERVER_NOT_CONFIGURED` if the key is missing, preventing unauthorized requests.**

The freestylefly/awesome-gpt-image-2 repository relies on APIMart as its core provider for server‑side image generation. Configuring the API key correctly ensures that the generation pipeline can authenticate requests, submit tasks, and poll for results without exposing credentials to the client.

## Obtain Your APIMart API Key

First, register an account at [APIMart](https://apimart.ai) and generate a personal API key from your dashboard. This key authorizes every image generation request made by your deployed application.

## Configure the Environment Variable

The application expects the key in the `APIMART_API_KEY` environment variable. The repository includes a template file demonstrating the required entry:

```dotenv

# .env.example

APIMART_API_KEY=

```

For local development, create a `.env` file in the project root:

```dotenv
APIMART_API_KEY=sk_live_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
VITE_SUPABASE_URL=https://your-project.supabase.co
VITE_SUPABASE_ANON_KEY=your-anon-key

```

### Production Deployment on Vercel

When deploying to Vercel, define `APIMART_API_KEY` as a **Sensitive** environment variable. This prevents the key from appearing in deployment logs or edge function traces. Navigate to your project settings, add the variable, and mark it as sensitive before redeploying.

## Runtime Detection and Validation

The helper `getApimartConfig()` defined in [`api/_lib/apimart.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/api/_lib/apimart.js) (line 14) reads the environment variable at runtime and returns a configuration object with a validation flag:

```javascript
// api/_lib/apimart.js
export function getApimartConfig() {
  const apiKey = String(process.env.APIMART_API_KEY || '').trim();
  return { baseUrl: APIMART_API_BASE_URL, apiKey, configured: Boolean(apiKey) };
}

```

The `configured` boolean indicates whether a non‑empty API key is present. The image generation handler in [`api/generate-image.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/api/generate-image.js) (lines 11‑13) checks this flag before processing any requests. If the key is absent, the endpoint immediately returns the error code `SERVER_NOT_CONFIGURED`, ensuring that no unauthenticated calls reach the APIMart API.

## Submitting Authenticated Generation Requests

When handling valid requests, the server uses `submitApimartGeneration()` to forward tasks to APIMart. This function retrieves the API key from `getApimartConfig()` and attaches it as a Bearer token in the Authorization header (lines 40‑48 of [`api/_lib/apimart.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/api/_lib/apimart.js)):

```javascript
const response = await fetch(`${baseUrl}/api/v1/images/generations`, {
  method: 'POST',
  headers: {
    'Authorization': `Bearer ${config.apiKey}`,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify(buildApimartGenerationPayload(options)),
});

```

The payload is constructed by `buildApimartGenerationPayload()` in [`shared/apimart.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/shared/apimart.js) (line 8), which formats the prompt, language, and webhook URL according to APIMart’s API specification. The returned task ID is stored in Supabase (`generation_reservations`) and later polled via `getApimartTask()`.

## Error Handling and Debugging

If the API key is invalid, expired, or rate limits are exceeded, the `apimartErrorCode()` function in [`shared/apimart.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/shared/apimart.js) (lines 70‑78) maps HTTP status codes to descriptive error codes for client feedback:

- **401 Unauthorized**: The API key is missing or invalid
- **429 Too Many Requests**: Rate limit exceeded on your APIMart account
- **SERVER_NOT_CONFIGURED**: The `APIMART_API_KEY` environment variable is empty or whitespace (detected before any network request)

Check your server logs for these specific codes during the first generation attempt to verify correct configuration.

## Summary

- Store your APIMart API key in the `APIMART_API_KEY` environment variable as shown in `.env.example`
- Mark the variable as **Sensitive** when deploying to Vercel to prevent leakage in logs
- The `getApimartConfig()` helper in [`api/_lib/apimart.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/api/_lib/apimart.js) validates key presence via the `configured` flag
- Missing keys trigger the `SERVER_NOT_CONFIGURED` error before any external API calls occur
- All authenticated requests use Bearer token authentication via the `Authorization` header against the APIMart generations endpoint

## Frequently Asked Questions

### What happens if I forget to set the APIMART_API_KEY in production?

The application returns the `SERVER_NOT_CONFIGURED` error immediately. As implemented in [`api/generate-image.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/api/generate-image.js) (lines 11‑13), the endpoint checks the `configured` flag returned by `getApimartConfig()` before submitting any requests, ensuring graceful failure without exposing stack traces or implementation details to the client.

### Can I rotate the API key without redeploying the application?

Yes. Since `getApimartConfig()` reads `process.env.APIMART_API_KEY` at runtime (line 14 of [`api/_lib/apimart.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/api/_lib/apimart.js)), updating the environment variable in your hosting platform (Vercel, AWS Lambda, etc.) takes effect immediately for subsequent requests without requiring a new build or deployment.

### How does the application handle invalid or expired API keys?

The `submitApimartGeneration()` function captures HTTP 401 responses and passes them through `apimartErrorCode()` in [`shared/apimart.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/shared/apimart.js) (lines 70‑78), mapping authentication failures to standardized error codes. The error propagates back to the client through the generation handler without crashing the server or retrying the request.

### Is the API key ever exposed to the client browser?

No. The key remains strictly server‑side. The `getApimartConfig()` function runs only within serverless functions located in [`api/_lib/apimart.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/api/_lib/apimart.js), and the repository’s architecture ensures that environment variables are never bundled into client‑side JavaScript or visible in network traces from the browser.