Skip to content
SamplePreview build: teacher profiles, ratings, reviews and lesson counts are sample data.
All tutors

API Key Safety and Secrets Handling

Keep model API keys out of code, repos, browsers and logs, and know exactly what to do if one leaks.

By Farid Haddad Beginner Building with LLM APIs 4.7(3) 32 lessons taught Sample

This tutor is free. Your lesson starts right away.

A taste of a lesson

One question and the answer, as this tutor gives it.

API Key Safety and Secrets Handling AI tutor following Farid Haddad's plan
Student:

I pushed my API key to a public repo, then deleted it in the next commit. Is that enough?

Tutor:

No. The key is still in your git history, and public repositories are scanned by automated bots, sometimes within minutes. Treat the key as stolen. Right now: revoke or rotate it in your provider's console, put the new key in an environment variable or .env file that is in .gitignore, and check your usage page for requests you did not make. Cleaning history can come later; rotation comes first. Have you revoked the old key yet?

Written by the teacher as an example. In your lesson the tutor answers your own questions, and like any AI it can be wrong.

What you will be able to do

  • Store keys safely in development and production environments
  • Explain why browsers and mobile apps must never hold API keys
  • Find the common leak paths: git history, logs, notebooks and screenshots
  • Limit damage with separate keys, scopes, spending caps and quotas
  • Respond to a leaked key quickly and in the right order

Lesson plan

6 lessons. Pick one to start there.

  1. 1 What a key can do in the wrong hands Understand the cost and data risks of a leaked key. Start
  2. 2 Keys in development Load keys from the environment and keep them out of code and notebooks. Start
  3. 3 Keys in production and in clients Keep keys on servers only and route client calls through your backend. Start
  4. 4 How keys actually leak Recognise the less obvious leak paths and close them. Start
  5. 5 Limiting blast radius Reduce the damage any single leak could cause. Start
  6. 6 Leak response drill Practise the steps to take the moment a leak is suspected. Start

Try asking

Tap a question to start a lesson with it.

About this tutor

For beginners and small teams building with model APIs who want to avoid the most expensive beginner mistake: a leaked key. You learn where keys should live during development and in production, why browsers and mobile apps can never hold them, how keys leak through git history, logs, screenshots and chat messages, and how to limit the damage with separate keys per environment, least privilege, spending caps and rotation. You practise a leak response from discovery to revocation. Short, practical and free, because everyone building with APIs should know this.

Reviews

4.7

3 ratingsSample

  • Ama O.Sample

    The leak drill was useful. I did not know authorization headers could end up in our error tracker. We added redaction the same day.

  • Bruno C.Sample

    I had my key in front end code for a demo. This explained why that is a real risk and how to proxy through a tiny backend. Free and important.

  • Felipe R.Sample

    Short and clear. Would have liked a bit more on CI secrets, but everything a beginner needs is here.

About the teacher

Farid Haddad

Keeps LLM features fast, affordable and available as traffic grows: cost, caching, retries and observability

9 tutors 4.5(19) 347 lessons taught Sample

Most of my working life has been on platform and reliability teams, and these days I spend it on LLM features: the bills that surprise people, the 429 errors on launch day, the logs nobody can read. I teach the operational side of building with model APIs. We estimate costs before writing code, add retries that do not make outages...

See Farid's profile and tutors