Is your API key really private? A quick check for your app

App CheckControlled demo · fake data

The short answer

Your secret API key isn't on the screen, but it can still be in the code your app sends to every visitor. On a computer, open your app, press F12, then Ctrl+Shift+F, and search for the first few characters of your secret key. If it shows up, anyone can copy it and run up your bill.

What to do

  1. On a computer, open your app and press F12.
  2. Press Ctrl+Shift+F (Cmd+Option+F on a Mac) and search for the first few characters of your secret key.
  3. If it shows up: call the API from your server, keep the key there, and replace the old key.

Good to know

  • Some keys are meant to be public: Stripe pk_ keys and the Supabase anon key. Secret keys (sk_ keys, service_role, AI API keys) never are.

How we checked it

We ran this in a demo app with fake data on 30 Sept 2026, and the video shows the result. Try it on your own app with test accounts and test data, never real users' data.

Related