Is your API key really private? A quick check for your app
App CheckControlled demo · fake data
Demo built and run 30 Sept 2026 · Published 1 Oct 2026 · Last reviewed 1 Oct 2026 · By Ctrl+Z Therapy (how we test)
The short answer
Your secret API key isn't on the screen, but it can still be in the code your app sends to every visitor. On a computer, open your app, press F12, then Ctrl+Shift+F, and search for the first few characters of your secret key. If it shows up, anyone can copy it and run up your bill.
What to do
- On a computer, open your app and press F12.
- Press Ctrl+Shift+F (Cmd+Option+F on a Mac) and search for the first few characters of your secret key.
- If it shows up: call the API from your server, keep the key there, and replace the old key.
Good to know
- Some keys are meant to be public: Stripe pk_ keys and the Supabase anon key. Secret keys (sk_ keys, service_role, AI API keys) never are.
How we checked it
We ran this in a demo app with fake data on 30 Sept 2026, and the video shows the result. Try it on your own app with test accounts and test data, never real users' data.