API Key Safety and Secrets Handling
Keep model API keys out of code, repos, browsers and logs, and know exactly what to do if one leaks.
A taste of a lesson
I pushed my API key to a public repo, then deleted it in the next commit. Is that enough?
No. The key is still in your git history, and public repositories are scanned by automated bots, sometimes within minutes. Treat the key as stolen. Right now: revoke or rotate it in your provider's console, put the new key in an environment variable or .env file that is in .gitignore, and check your usage page for requests you did not make. Cleaning history can come later; rotation comes first. Have you revoked the old key yet?
Written by the teacher as an example. In your lesson the tutor answers your own questions, and like any AI it can be wrong.
What you will be able to do
- Store keys safely in development and production environments
- Explain why browsers and mobile apps must never hold API keys
- Find the common leak paths: git history, logs, notebooks and screenshots
- Limit damage with separate keys, scopes, spending caps and quotas
- Respond to a leaked key quickly and in the right order
Lesson plan
- 1 What a key can do in the wrong hands Understand the cost and data risks of a leaked key. Start
- 2 Keys in development Load keys from the environment and keep them out of code and notebooks. Start
- 3 Keys in production and in clients Keep keys on servers only and route client calls through your backend. Start
- 4 How keys actually leak Recognise the less obvious leak paths and close them. Start
- 5 Limiting blast radius Reduce the damage any single leak could cause. Start
- 6 Leak response drill Practise the steps to take the moment a leak is suspected. Start
Try asking
About this tutor
For beginners and small teams building with model APIs who want to avoid the most expensive beginner mistake: a leaked key. You learn where keys should live during development and in production, why browsers and mobile apps can never hold them, how keys leak through git history, logs, screenshots and chat messages, and how to limit the damage with separate keys per environment, least privilege, spending caps and rotation. You practise a leak response from discovery to revocation. Short, practical and free, because everyone building with APIs should know this.
Reviews
4.7
3 ratingsSample
- Ama O.Sample
The leak drill was useful. I did not know authorization headers could end up in our error tracker. We added redaction the same day.
- Bruno C.Sample
I had my key in front end code for a demo. This explained why that is a real risk and how to proxy through a tiny backend. Free and important.
- Felipe R.Sample
Short and clear. Would have liked a bit more on CI secrets, but everything a beginner needs is here.
About the teacher
Keeps LLM features fast, affordable and available as traffic grows: cost, caching, retries and observability
9 tutors 347 lessons taught Sample
Most of my working life has been on platform and reliability teams, and these days I spend it on LLM features: the bills that surprise people, the 429 errors on launch day, the logs nobody can read. I teach the operational side of building with model APIs. We estimate costs before writing code, add retries that do not make outages...
See Farid's profile and tutorsMore like this
Other tutors on the same or nearby topics.