Legal
How to Avoid Committing an API Key
An API key written in an HTML or JavaScript file is readable by anyone who opens the page source. Do not paste it into a project you deploy from app.clincoo.buzz.
Use an environment variable, not a string in code
Store the secret in the project environment settings, and read it from a server process when that feature exists. In the browser, treat every constant as visible. Call the service through an endpoint you control, not with the key in the client.
Check before you commit
Before the first or next commit in editor.clincoo.buzz, search files for sk_, api_key, and token. If you find one, move it, then commit the removal.
If it already shipped
Rotate the key at the provider, treat the old key as leaked, and deploy again. Deleting the line does not pull back copies people already downloaded.