Store configuration in environment variables, not code:
// .env file
API_KEY=secret123
DATABASE_URL=postgres://...
// In code
const apiKey = process.env.API_KEY;
Use dotenv package to load .env files in development. Never commit .env files.