How to Configure API Keys for the mvanhorn/last30days-skill: Complete Setup Guide
Configure API keys for the mvanhorn/last30days-skill using environment variables, global dotfiles, or per-project configs, with the loader at scripts/lib/env.py determining precedence automatically.
The mvanhorn/last30days-skill requires valid credentials for services like OpenAI, X/Twitter, Reddit, and web search providers to function. According to the source code in scripts/lib/env.py, the skill implements a hierarchical configuration system that checks three distinct locations in order of precedence, allowing you to manage secrets securely across different environments.
Configuration Hierarchy and Precedence
The get_config() function in scripts/lib/env.py (lines 44-68) resolves credentials by merging values from three sources, with later sources overriding earlier ones:
- Process environment variables (e.g.,
OPENAI_API_KEY,XAI_API_KEY) — highest priority - Per-project config —
.claude/last30days.envin the current project directory or any parent directory - Global config —
~/.config/last30days/.envin the user's home directory — lowest priority
The loader walks up the directory tree from the current working directory to find per-project files (lines 98-112), stops at the home directory or filesystem root, and merges values with merged_env = {**file_env, **project_env} (lines 30-32). The final configuration dictionary includes a _CONFIG_SOURCE key indicating whether values originated from a project file, global file, or solely from environment variables (lines 71-76).
Step-by-Step Configuration Methods
Environment Variables (Recommended for CI/CD)
Export variables directly in your shell for immediate effect. These take precedence over any .env file.
export OPENAI_API_KEY="sk-..."
export XAI_API_KEY="..."
export BRAVE_API_KEY="..."
export SCRAPECREATORS_API_KEY="..."
export OPENROUTER_API_KEY="..."
export PARALLEL_API_KEY="..."
To verify the skill recognizes these, check the _CONFIG_SOURCE field in the resolved config.
Global Configuration File
Create the default global directory and file for user-wide settings that apply when no project-specific file exists:
mkdir -p "$HOME/.config/last30days"
cat > "$HOME/.config/last30days/.env" <<EOF
OPENAI_API_KEY=sk-...
XAI_API_KEY=...
BRAVE_API_KEY=...
EOF
chmod 600 "$HOME/.config/last30days/.env"
The load_env_file function (lines 66-87 in scripts/lib/env.py) reads this file if LAST30DAYS_CONFIG_DIR is unset or empty, and warns if permissions are too permissive.
Per-Project Configuration
Place a .claude/last30days.env file in your project root to override global settings for that specific project. The loader searches from the current working directory upward (lines 98-112):
mkdir -p .claude
cat > .claude/last30days.env <<EOF
OPENAI_API_KEY=sk-proj-...
XAI_API_KEY=proj-xai-key
EOF
Project-level entries override global ones, allowing different API keys for different codebases.
Custom Configuration Directory
Point to a non-standard location using the LAST30DAYS_CONFIG_DIR environment variable. The skill looks for a .env file inside this directory (lines 11-24):
export LAST30DAYS_CONFIG_DIR="/opt/shared-configs/last30days"
# File must exist at: /opt/shared-configs/last30days/.env
Disabling File-Based Configuration
Set LAST30DAYS_CONFIG_DIR to an empty string to prevent the skill from loading any .env files, relying exclusively on process environment variables:
export LAST30DAYS_CONFIG_DIR=""
This is useful for clean CI runs where you want to ensure no accidental local configs interfere.
How Configuration Drives Service Availability
The resolved configuration dictionary determines which backends are active. Helper functions in scripts/lib/env.py check for specific keys:
is_reddit_available()— Returns true ifSCRAPECREATORS_API_KEYexists or a valid OpenAI key is present (OpenAI serves as a fallback for Reddit processing)get_x_source()— Prefers a locally-installed Bird client, then falls back toXAI_API_KEYfor X/Twitter accesshas_web_search_keys()— True if any ofOPENROUTER_API_KEY,PARALLEL_API_KEY, orBRAVE_API_KEYis present, enabling web search capabilities
These checks occur at runtime, so missing keys simply disable specific features rather than causing hard failures.
Programmatic Configuration Access
Import the loader directly to inspect resolved values in Python scripts:
from scripts.lib.env import get_config
cfg = get_config()
print("OpenAI key:", cfg["OPENAI_API_KEY"])
print("X-AI key:", cfg["XAI_API_KEY"])
print("Source:", cfg["_CONFIG_SOURCE"])
This returns the merged configuration including the source attribution, useful for debugging which file provided a specific credential.
Summary
- Environment variables override everything — Set
OPENAI_API_KEY,XAI_API_KEY,BRAVE_API_KEY, and others directly for CI/CD or temporary overrides. - Per-project files override global — Use
.claude/last30days.envin project roots for repository-specific credentials. - Global fallback — Store default keys in
~/.config/last30days/.envfor system-wide availability. - Custom paths — Redirect with
LAST30DAYS_CONFIG_DIR=/custom/pathor disable files entirely withLAST30DAYS_CONFIG_DIR="". - Security — Set permissions to
600on.envfiles; the loader warns if files are world-readable. - Service mapping — Reddit requires
SCRAPECREATORS_API_KEYor OpenAI; X/Twitter uses Bird orXAI_API_KEY; web search needs Brave, OpenRouter, or Parallel keys.
Frequently Asked Questions
What is the exact precedence order for configuration sources?
The get_config() function in scripts/lib/env.py loads sources in this strict order: first process environment variables, then per-project .claude/last30days.env (walking up from CWD), then global ~/.config/last30days/.env. Each subsequent layer overrides values from the previous layer, so an OPENAI_API_KEY in your shell environment will replace one found in a project file.
Can I use a single environment variable to change where config files are stored?
Yes. Set LAST30DAYS_CONFIG_DIR to any directory path, and the skill will look for .env inside that directory instead of the default ~/.config/last30days. Set it to an empty string (LAST30DAYS_CONFIG_DIR="") to disable file loading completely, forcing the skill to use only process environment variables.
Which API keys are required for Reddit and X/Twitter functionality?
For Reddit access, the skill requires either SCRAPECREATORS_API_KEY or a valid OPENAI_API_KEY (which serves as a fallback processing method). For X/Twitter, the skill first attempts to use a locally-installed Bird client; if unavailable, it requires XAI_API_KEY. These checks occur in is_reddit_available() and get_x_source() within scripts/lib/env.py.
How does the skill warn about insecure file permissions?
When loading .env files from disk, the configuration loader checks file permissions and emits a warning if the file is readable by other users. The recommended security practice is chmod 600 on your ~/.config/last30days/.env or .claude/last30days.env files to ensure only the owner can read sensitive API keys.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →