When building mobile or web apps, security is paramount.

Some API keys belong on the client, others on the server—but do you know which is which? 🤔

Here are some guidelines to help you decide.

API keys storage: Client or Server?

Additional Resources

For more in-depth guidance about securing API keys, read this article:

Some API keys must be stored on the server and never transmitted to the client. Dart Shelf works great in this scenario, and this article covers all the details:

If you work with Firebase Cloud Functions and want to learn about best practices for securing your server-side keys, this guide has you covered:

Happy coding!