How to Configure APIMart API Keys for Production‑Ready Image Generation

Store your APIMart API key in the APIMART_API_KEY environment variable; the application detects it via getApimartConfig() in api/_lib/apimart.js and returns SERVER_NOT_CONFIGURED if the key is missing, preventing unauthorized requests.

The freestylefly/awesome-gpt-image-2 repository relies on APIMart as its core provider for server‑side image generation. Configuring the API key correctly ensures that the generation pipeline can authenticate requests, submit tasks, and poll for results without exposing credentials to the client.

Obtain Your APIMart API Key

First, register an account at APIMart and generate a personal API key from your dashboard. This key authorizes every image generation request made by your deployed application.

Configure the Environment Variable

The application expects the key in the APIMART_API_KEY environment variable. The repository includes a template file demonstrating the required entry:


# .env.example

APIMART_API_KEY=

For local development, create a .env file in the project root:

APIMART_API_KEY=sk_live_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
VITE_SUPABASE_URL=https://your-project.supabase.co
VITE_SUPABASE_ANON_KEY=your-anon-key

Production Deployment on Vercel

When deploying to Vercel, define APIMART_API_KEY as a Sensitive environment variable. This prevents the key from appearing in deployment logs or edge function traces. Navigate to your project settings, add the variable, and mark it as sensitive before redeploying.

Runtime Detection and Validation

The helper getApimartConfig() defined in api/_lib/apimart.js (line 14) reads the environment variable at runtime and returns a configuration object with a validation flag:

// api/_lib/apimart.js
export function getApimartConfig() {
  const apiKey = String(process.env.APIMART_API_KEY || '').trim();
  return { baseUrl: APIMART_API_BASE_URL, apiKey, configured: Boolean(apiKey) };
}

The configured boolean indicates whether a non‑empty API key is present. The image generation handler in api/generate-image.js (lines 11‑13) checks this flag before processing any requests. If the key is absent, the endpoint immediately returns the error code SERVER_NOT_CONFIGURED, ensuring that no unauthenticated calls reach the APIMart API.

Submitting Authenticated Generation Requests

When handling valid requests, the server uses submitApimartGeneration() to forward tasks to APIMart. This function retrieves the API key from getApimartConfig() and attaches it as a Bearer token in the Authorization header (lines 40‑48 of api/_lib/apimart.js):

const response = await fetch(`${baseUrl}/api/v1/images/generations`, {
  method: 'POST',
  headers: {
    'Authorization': `Bearer ${config.apiKey}`,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify(buildApimartGenerationPayload(options)),
});

The payload is constructed by buildApimartGenerationPayload() in shared/apimart.js (line 8), which formats the prompt, language, and webhook URL according to APIMart’s API specification. The returned task ID is stored in Supabase (generation_reservations) and later polled via getApimartTask().

Error Handling and Debugging

If the API key is invalid, expired, or rate limits are exceeded, the apimartErrorCode() function in shared/apimart.js (lines 70‑78) maps HTTP status codes to descriptive error codes for client feedback:

  • 401 Unauthorized: The API key is missing or invalid
  • 429 Too Many Requests: Rate limit exceeded on your APIMart account
  • SERVER_NOT_CONFIGURED: The APIMART_API_KEY environment variable is empty or whitespace (detected before any network request)

Check your server logs for these specific codes during the first generation attempt to verify correct configuration.

Summary

  • Store your APIMart API key in the APIMART_API_KEY environment variable as shown in .env.example
  • Mark the variable as Sensitive when deploying to Vercel to prevent leakage in logs
  • The getApimartConfig() helper in api/_lib/apimart.js validates key presence via the configured flag
  • Missing keys trigger the SERVER_NOT_CONFIGURED error before any external API calls occur
  • All authenticated requests use Bearer token authentication via the Authorization header against the APIMart generations endpoint

Frequently Asked Questions

What happens if I forget to set the APIMART_API_KEY in production?

The application returns the SERVER_NOT_CONFIGURED error immediately. As implemented in api/generate-image.js (lines 11‑13), the endpoint checks the configured flag returned by getApimartConfig() before submitting any requests, ensuring graceful failure without exposing stack traces or implementation details to the client.

Can I rotate the API key without redeploying the application?

Yes. Since getApimartConfig() reads process.env.APIMART_API_KEY at runtime (line 14 of api/_lib/apimart.js), updating the environment variable in your hosting platform (Vercel, AWS Lambda, etc.) takes effect immediately for subsequent requests without requiring a new build or deployment.

How does the application handle invalid or expired API keys?

The submitApimartGeneration() function captures HTTP 401 responses and passes them through apimartErrorCode() in shared/apimart.js (lines 70‑78), mapping authentication failures to standardized error codes. The error propagates back to the client through the generation handler without crashing the server or retrying the request.

Is the API key ever exposed to the client browser?

No. The key remains strictly server‑side. The getApimartConfig() function runs only within serverless functions located in api/_lib/apimart.js, and the repository’s architecture ensures that environment variables are never bundled into client‑side JavaScript or visible in network traces from the browser.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →