Verifiedapp Blog
Home All posts

Tag

#api-keys

Secrets

OpenAI & Anthropic API keys in client code: the new #1 leak

Adding an AI feature is a five-minute job, and that is exactly the problem: the quickest path drops your OpenAI or Anthropic key into code the browser downloads.

Jul 20, 2026 · 3 min read
Secrets

Stripe keys in your frontend: live vs. restricted vs. webhook secrets

Stripe gives you several kinds of key, and only one is meant for the browser. Mixing them up is the common mistake — here is which goes where.

Jul 2, 2026 · 3 min read
Secrets

The most common way API keys leak from production sites

API keys do not usually leak through clever hacks. They leak because a key meant for the server ends up in code the browser downloads. Here is the pattern, and the fix.

Apr 16, 2026 · 3 min read
© VerifiedApp — automated security scanning & trust badges. RSS