Backend only
Never place a key in browser JavaScript, a mobile application, or a URL.
Least privilege
A runtime key does not need to read or publish configuration.
One key per environment
Separate development, staging, production, and automation.
Immediate revocation
Revoke every lost or exposed key before creating a replacement.
Recommended storage
- an environment variable injected at deployment;
- your cloud provider’s secret manager;
- never Git, screenshots, tickets, or logs;
- redact
Authorizationheaders from observability.
Rotate without interruption
- create a second key with the same minimal scopes;
- deploy it to your backend;
- verify API calls;
- revoke the old key.