WEBSITESfor Normal People2026

Part V: The Part of Fourteens (lists you'll come back to)A

Appendix AAppendix A

Appendix A: Every click you'll make, and every key

2 min read

Fourteen clicks. Count them.

The whole guide, from nothing to a live site, as a list of what a human has to do. Everything not on this list is the agent.

Your clicks

Your clicks, ticked off

0/ 15

Fourteen things. Most take under a minute.

Every key

Secret in the vaultCreated byPathUsed for
CLOUDFLARE_BOOTSTRAP_TOKENYouAllLets the agent make its own Cloudflare token. Delete after setup.
CLOUDFLARE_API_TOKENAgentAllDeploys, DNS, database, storage, email, Turnstile
CLOUDFLARE_DEPLOY_TOKENAgentAllDeploy-only token for GitHub Actions
CLOUDFLARE_ACCOUNT_IDAgentAllWhich Cloudflare account
TURNSTILE_SECRET_KEYAgentFormsSpam protection
PAYLOAD_SECRETAgentBThe CMS's internal encryption
PAYLOAD_ADMIN_PASSWORDAgentBYour first CMS login (change it after)
STRIPE_SECRET_KEYYouCPayments. Test key first, live key at launch
STRIPE_WEBHOOK_SECRETAgentCConfirms payments really happened
GOOGLE_SERVICE_ACCOUNT_JSONAgentAnalyticsGA4, Tag Manager, Search Console

Not in the vault:

  • Bitwarden access token: in your computer's keychain, because it unlocks the vault.
  • GitHub login: kept by the GitHub CLI in your computer's keychain after you click Authorize.

When keys expire

The agent's Cloudflare token lasts a year, and GitHub's login lasts until you revoke it. When one expires the agent will say so. Tell it "make a new one", and if it needs a new bootstrap token, repeat click 7.

On a phone, swipe left and right to turn pages.