A contact form or booking flow often begins in a browser, but the email request belongs on the server. If a private sending key is included in client-side JavaScript, anyone who downloads that code can extract it. Hiding the button does not protect the credential.
Keep credentials in the server environment
Use a server-only environment variable such as SENDAR_API_KEY. Do not give it a NEXT_PUBLIC prefix. Your browser submits the minimum application input to your server, and the server decides whether that request is allowed to produce an email.
The Sendar Next.js starter demonstrates a preview-first flow. The local preview lets you inspect the proposed message before enabling a real send. This preview is part of the starter; it is not a general REST dry-run endpoint.
Authorise the action, not just the payload
An API route that accepts an arbitrary recipient and message from any visitor can become an open sending relay. For a receipt, derive the destination from the authenticated order. For an internal contact form, keep the destination configured on the server and validate the submitted fields.
Apply appropriate authentication, input limits and rate controls to your application's route. Never assume the browser's validation is the final check. Escape user-supplied text before inserting it into HTML, and avoid constructing links from untrusted URLs.
Give each event a stable identity
Use the committed application event to choose your Idempotency-Key. Repeated button clicks should not create unrelated identities for the same receipt. Keep the request payload stable for a retry and record the returned message ID.
If a timeout occurs, inspect the result before trying a new request. An HTTP connection can fail after the email was accepted. Your user-facing response can acknowledge the completed booking while email delivery is investigated separately.
Take the example into production deliberately
The starter's demonstration endpoint is not a finished public contact-form service. Its live mode uses explicitly configured recipients, and the demo endpoint is disabled in production. Use it to understand the request, then connect that request to your own authorised application workflow. Verify your domain and send to a controlled address before opening the flow to customers.