← Back to category

Legal

How to Avoid Committing an API Key

An API key written in an HTML or JavaScript file is readable by anyone who opens the page source. Do not paste it into a project you deploy from app.clincoo.buzz.

Use an environment variable, not a string in code

Store the secret in the project environment settings, and read it from a server process when that feature exists. In the browser, treat every constant as visible. Call the service through an endpoint you control, not with the key in the client.

Check before you commit

Before the first or next commit in editor.clincoo.buzz, search files for sk_, api_key, and token. If you find one, move it, then commit the removal.

If it already shipped

Rotate the key at the provider, treat the old key as leaked, and deploy again. Deleting the line does not pull back copies people already downloaded.