Context: In Next.js apps that call Alibaba Cloud Model Studio (the LLM platform Alibaba also calls Bailian) through its OpenAI-compatible endpoint, the community convention is to keep the API key in a BAILIAN_API_KEY variable inside `.env.local`, read only from server-side code. You create the key on the API-Key page of the Model Studio console. People search this when wiring Qwen/DashScope calls into a Ne

TL;DR: create the key in the Model Studio console, put BAILIAN_API_KEY in `.env.local` (gitignored, server-side only), and read it via `process.env.BAILIAN_API_KEY` in route handlers. The OpenAI-compatible base URL is `https://dashscope.aliyuncs.com/compatible-mode/v1`.

1. Get a key: open the Alibaba Cloud Model Studio console (modelstudio.console.alibabacloud.com for international, or the Beijing console), and create an API key on the API-Key page. Keys are region-scoped, so the key must match the region of the endpoint you call.
2. Create `.env.local` in the project root with one variable per line in the standard env-file format (shown here with placeholders, never commit real values):
```env
BAILIAN_API_KEY [your key]
BAILIAN_MODEL [model name, e.g. qwen3-max]
```
Success check: `npm run dev` starts with no key printed anywhere in the terminal or browser.

3. Read the key only in server code (route handlers, server actions), referencing `process.env.BAILIAN_API_KEY` where you build the client. Point your OpenAI client at the compatible-mode base URL with this key as the bearer credential. Success check: a chat completion request returns 200.

4. Add `.env.local` to `.gitignore` and never commit it. Never prefix the variable with `NEXT_PUBLIC_`, which would bundle the key into client JavaScript and expose it in the browser.

Variant phrasings: "bailian api key nextjs", "DASHSCOPE_API_KEY .env", "qwen api key environment variable", "model studio api key .env.local".

Mechanism (after the fix): Next.js loads `.env.local` into `process.env` at startup. The OpenAI-compatible endpoint authenticates the key as a bearer token on each request. Alibaba's own docs also use the name DASHSCOPE_API_KEY; the two names are interchangeable as long as your code reads the same name you set. Separate key classes exist for the Qwen Code CLI plans (BAILIAN_CODING_PLAN_API_KEY, BAILIAN_TOKEN_PLAN_API_KEY) and are not interchangeable with standard keys.

Edge cases: a key from the wrong region returns an auth error even when the value is correct; `sk-sp-` prefixed coding-plan keys do not work against the standard endpoint; in production, prefer the hosting platform's env-var store (e.g. Vercel project env vars) over a committed file.

Use this when: a Next.js app (or any Node server) calls Model Studio / Bailian models through the OpenAI-compatible endpoint and needs the key in local development.

Do NOT use this when: the key is needed in client components (it will leak; proxy through a route handler instead), when deploying via a platform secret store (use that instead of a file), or for the Qwen Code CLI itself, which has its own auth flow and plan-specific key names.