# IoT with the ESP32 — Arduino & Embedded C

Source: https://www.geekswithgeeks.com/en/arduino-embedded-c/esp32-iot

> Wi-Fi, HTTP, MQTT and keeping secrets out of git.

## Connecting a device to the network

The **ESP32** family adds Wi-Fi (and on many models Bluetooth) to an Arduino-compatible MCU running at 3.3 V. The Arduino core provides `WiFi.h` to join a network and `HTTPClient` for simple HTTP requests. For telemetry, **MQTT** is popular: devices publish small messages to topics on a **broker**, and other devices or dashboards subscribe; libraries such as PubSubClient implement it. Production devices should use TLS (for example `WiFiClientSecure` with a verified certificate), reconnect gracefully when Wi-Fi drops and never block the main loop forever waiting for the network. **Never hard-code Wi-Fi passwords or API keys in code you publish**: keep them in a separate header that is excluded from version control, and ship a template file instead. Library APIs change between core versions; check the docs.

## Join Wi-Fi and make an HTTP GET

ESP32 Arduino core. secrets.h is listed in .gitignore; the URL is a placeholder.

```cpp
#include <WiFi.h>
#include <HTTPClient.h>
#include "secrets.h"   // defines WIFI_SSID, WIFI_PASS (NOT committed)

void setup() {
  Serial.begin(115200);
  WiFi.mode(WIFI_STA);
  WiFi.begin(WIFI_SSID, WIFI_PASS);
  unsigned long start = millis();
  while (WiFi.status() != WL_CONNECTED && millis() - start < 15000) {
    delay(250);                       // bounded wait, not forever
  }
  if (WiFi.status() != WL_CONNECTED) {
    Serial.println("Wi-Fi failed; will retry later");
    return;
  }
  Serial.println(WiFi.localIP());

  HTTPClient http;
  http.begin("http://example.com/api/status");
  int code = http.GET();
  if (code > 0) Serial.println(http.getString());
  else Serial.printf("HTTP error %d\n", code);
  http.end();
}

void loop() {}
```

## Keeping secrets out of the repository

Project layout and ignore rule.

```text
MySensor/
  MySensor.ino
  secrets.h            <- real credentials, never committed
  secrets.example.h    <- committed template with dummy values

.gitignore:
  secrets.h

secrets.example.h:
  #define WIFI_SSID "your-network"
  #define WIFI_PASS "your-password"

If a secret was ever pushed: rotate it (change the password/key),
because removing it from the latest commit does not remove it from history.
```

## Plain HTTP and MQTT are readable

Without TLS, anyone on the network path can read and alter traffic. Use encrypted connections and per-device credentials for anything beyond a local experiment.

**Quiz:** Where should Wi-Fi credentials for a public project live?

- [x] In a separate file excluded from version control, with a committed template
- [ ] Directly in the main sketch so others can test it
- [ ] In a comment at the top of the README
- [ ] In the device name broadcast over Wi-Fi

*Answer:* In a separate file excluded from version control, with a committed template. Credentials pushed to a public repository must be considered leaked.
