# How to Configure API Keys for the mvanhorn/last30days-skill: Complete Setup Guide

> Learn how to configure API keys for mvanhorn/last30days-skill. This guide covers environment variables, dotfiles, and per-project settings for seamless integration.

- Repository: [Matt Van Horn/last30days-skill](https://github.com/mvanhorn/last30days-skill)
- Tags: how-to-guide
- Published: 2026-03-25

---

**Configure API keys for the mvanhorn/last30days-skill using environment variables, global dotfiles, or per-project configs, with the loader at [`scripts/lib/env.py`](https://github.com/mvanhorn/last30days-skill/blob/main/scripts/lib/env.py) determining precedence automatically.**

The mvanhorn/last30days-skill requires valid credentials for services like OpenAI, X/Twitter, Reddit, and web search providers to function. According to the source code in [`scripts/lib/env.py`](https://github.com/mvanhorn/last30days-skill/blob/main/scripts/lib/env.py), the skill implements a hierarchical configuration system that checks three distinct locations in order of precedence, allowing you to manage secrets securely across different environments.

## Configuration Hierarchy and Precedence

The `get_config()` function in [`scripts/lib/env.py`](https://github.com/mvanhorn/last30days-skill/blob/main/scripts/lib/env.py) (lines 44-68) resolves credentials by merging values from three sources, with later sources overriding earlier ones:

1. **Process environment variables** (e.g., `OPENAI_API_KEY`, `XAI_API_KEY`) — highest priority
2. **Per-project config** — `.claude/last30days.env` in the current project directory or any parent directory
3. **Global config** — `~/.config/last30days/.env` in the user's home directory — lowest priority

The loader walks up the directory tree from the current working directory to find per-project files (lines 98-112), stops at the home directory or filesystem root, and merges values with `merged_env = {**file_env, **project_env}` (lines 30-32). The final configuration dictionary includes a `_CONFIG_SOURCE` key indicating whether values originated from a project file, global file, or solely from environment variables (lines 71-76).

## Step-by-Step Configuration Methods

### Environment Variables (Recommended for CI/CD)

Export variables directly in your shell for immediate effect. These take precedence over any `.env` file.

```bash
export OPENAI_API_KEY="sk-..."
export XAI_API_KEY="..."
export BRAVE_API_KEY="..."
export SCRAPECREATORS_API_KEY="..."
export OPENROUTER_API_KEY="..."
export PARALLEL_API_KEY="..."

```

To verify the skill recognizes these, check the `_CONFIG_SOURCE` field in the resolved config.

### Global Configuration File

Create the default global directory and file for user-wide settings that apply when no project-specific file exists:

```bash
mkdir -p "$HOME/.config/last30days"
cat > "$HOME/.config/last30days/.env" <<EOF
OPENAI_API_KEY=sk-...
XAI_API_KEY=...
BRAVE_API_KEY=...
EOF
chmod 600 "$HOME/.config/last30days/.env"

```

The `load_env_file` function (lines 66-87 in [`scripts/lib/env.py`](https://github.com/mvanhorn/last30days-skill/blob/main/scripts/lib/env.py)) reads this file if `LAST30DAYS_CONFIG_DIR` is unset or empty, and warns if permissions are too permissive.

### Per-Project Configuration

Place a `.claude/last30days.env` file in your project root to override global settings for that specific project. The loader searches from the current working directory upward (lines 98-112):

```bash
mkdir -p .claude
cat > .claude/last30days.env <<EOF
OPENAI_API_KEY=sk-proj-...
XAI_API_KEY=proj-xai-key
EOF

```

Project-level entries override global ones, allowing different API keys for different codebases.

### Custom Configuration Directory

Point to a non-standard location using the `LAST30DAYS_CONFIG_DIR` environment variable. The skill looks for a `.env` file inside this directory (lines 11-24):

```bash
export LAST30DAYS_CONFIG_DIR="/opt/shared-configs/last30days"

# File must exist at: /opt/shared-configs/last30days/.env

```

### Disabling File-Based Configuration

Set `LAST30DAYS_CONFIG_DIR` to an empty string to prevent the skill from loading any `.env` files, relying exclusively on process environment variables:

```bash
export LAST30DAYS_CONFIG_DIR=""

```

This is useful for clean CI runs where you want to ensure no accidental local configs interfere.

## How Configuration Drives Service Availability

The resolved configuration dictionary determines which backends are active. Helper functions in [`scripts/lib/env.py`](https://github.com/mvanhorn/last30days-skill/blob/main/scripts/lib/env.py) check for specific keys:

- **`is_reddit_available()`** — Returns true if `SCRAPECREATORS_API_KEY` exists or a valid OpenAI key is present (OpenAI serves as a fallback for Reddit processing)
- **`get_x_source()`** — Prefers a locally-installed **Bird** client, then falls back to `XAI_API_KEY` for X/Twitter access
- **`has_web_search_keys()`** — True if any of `OPENROUTER_API_KEY`, `PARALLEL_API_KEY`, or `BRAVE_API_KEY` is present, enabling web search capabilities

These checks occur at runtime, so missing keys simply disable specific features rather than causing hard failures.

## Programmatic Configuration Access

Import the loader directly to inspect resolved values in Python scripts:

```python
from scripts.lib.env import get_config

cfg = get_config()

print("OpenAI key:", cfg["OPENAI_API_KEY"])
print("X-AI key:", cfg["XAI_API_KEY"])
print("Source:", cfg["_CONFIG_SOURCE"])

```

This returns the merged configuration including the source attribution, useful for debugging which file provided a specific credential.

## Summary

- **Environment variables override everything** — Set `OPENAI_API_KEY`, `XAI_API_KEY`, `BRAVE_API_KEY`, and others directly for CI/CD or temporary overrides.
- **Per-project files override global** — Use `.claude/last30days.env` in project roots for repository-specific credentials.
- **Global fallback** — Store default keys in `~/.config/last30days/.env` for system-wide availability.
- **Custom paths** — Redirect with `LAST30DAYS_CONFIG_DIR=/custom/path` or disable files entirely with `LAST30DAYS_CONFIG_DIR=""`.
- **Security** — Set permissions to `600` on `.env` files; the loader warns if files are world-readable.
- **Service mapping** — Reddit requires `SCRAPECREATORS_API_KEY` or OpenAI; X/Twitter uses Bird or `XAI_API_KEY`; web search needs Brave, OpenRouter, or Parallel keys.

## Frequently Asked Questions

### What is the exact precedence order for configuration sources?

The `get_config()` function in [`scripts/lib/env.py`](https://github.com/mvanhorn/last30days-skill/blob/main/scripts/lib/env.py) loads sources in this strict order: first process environment variables, then per-project `.claude/last30days.env` (walking up from CWD), then global `~/.config/last30days/.env`. Each subsequent layer overrides values from the previous layer, so an `OPENAI_API_KEY` in your shell environment will replace one found in a project file.

### Can I use a single environment variable to change where config files are stored?

Yes. Set `LAST30DAYS_CONFIG_DIR` to any directory path, and the skill will look for `.env` inside that directory instead of the default `~/.config/last30days`. Set it to an empty string (`LAST30DAYS_CONFIG_DIR=""`) to disable file loading completely, forcing the skill to use only process environment variables.

### Which API keys are required for Reddit and X/Twitter functionality?

For Reddit access, the skill requires either `SCRAPECREATORS_API_KEY` or a valid `OPENAI_API_KEY` (which serves as a fallback processing method). For X/Twitter, the skill first attempts to use a locally-installed Bird client; if unavailable, it requires `XAI_API_KEY`. These checks occur in `is_reddit_available()` and `get_x_source()` within [`scripts/lib/env.py`](https://github.com/mvanhorn/last30days-skill/blob/main/scripts/lib/env.py).

### How does the skill warn about insecure file permissions?

When loading `.env` files from disk, the configuration loader checks file permissions and emits a warning if the file is readable by other users. The recommended security practice is `chmod 600` on your `~/.config/last30days/.env` or `.claude/last30days.env` files to ensure only the owner can read sensitive API keys.