Is This API Key Safe in Frontend? is a free tool that classifies likely credential types and explains where they belong. Check an API key, token or environment variable before adding it to a client bundle. You can use just the variable name instead of a real credential. All analysis runs in your browser; nothing is uploaded or saved.
How to check frontend API key safety
- Choose Single value or .env / environment block.
- Enter a variable name, a value, or both. For a block, paste literal
KEY=valueassignments; blank values work too. - Select Analyze. Read the classification, confidence and evidence for each item.
- Review Potential frontend exposure and follow the provider-specific recommended actions.
- Select Reset to clear all inputs and findings.
Public does not necessarily mean unrestricted
An identifier, such as an AWS access key ID, is not enough to authenticate by itself. A publishable or client key, such as Stripe’s publishable key, is deliberately distributed to users. A restricted browser key, such as a Google Maps key, needs application and API restrictions. An authentication secret authorizes its holder. A service or admin credential can grant broader access or bypass normal policies. These last two types belong on trusted servers.
Supabase anon keys rely on Row Level Security and policies. Firebase web keys rely on Security Rules and appropriate API restrictions. A Sentry DSN accepts events without granting account access, but event abuse still warrants filters and rate limits. “Public” describes intended placement, not unlimited access or guaranteed security.
Exposure, recovery and limits
NEXT_PUBLIC_, VITE_, REACT_APP_ and similar prefixes can ship values to users. Renaming an OpenAI secret to NEXT_PUBLIC_OPENAI_API_KEY keeps its permissions and exposes it. If an actual secret was deployed publicly, revoke or rotate it, move calls behind your backend, and redeploy. Check usage and billing, and remove leaked copies from repositories and artifacts. Use theHAR Analyzer & Sanitizer before sharing a traffic capture during investigation.
This is a classification helper, not a secret scanner or security certification. Names can be inaccurate, prefixes can overlap, and decoded JWT claims are unverified. A bare Google key cannot distinguish Maps from Gemini. UNKNOWN means you must confirm the credential type before exposing it. The parser accepts up to 64 KiB and 100 variables, reports malformed assignments, and never expands references or executes code.
Frequently asked questions
Is it safe to put API keys in frontend code?
Only keys designed for client use belong there. Authentication secrets, admin keys and service-role credentials must stay on a trusted backend. Browser keys can still need restrictions and authorization policies.
Is a Stripe publishable key public?
Yes. Stripe publishable keys are intended for frontend SDKs. Secret and restricted Stripe API keys must stay server-only, even in test mode.
Is the Supabase anon key safe to expose?
Supabase anon and publishable keys are intended for clients, but data security depends on Row Level Security, policies and grants. Never expose service_role or secret keys, which can bypass RLS.
Is a Firebase API key secret?
A Firebase web API key is not an authorization secret. Apply appropriate restrictions, Security Rules and App Check where supported. Firebase service-account private keys and Gemini API keys are different and must stay secret.
Does NEXT_PUBLIC make an API key safe?
No. NEXT_PUBLIC normally causes a value to be embedded into Next.js client bundles. VITE_, REACT_APP_ and similar prefixes also expose configuration; they do not remove the permissions of a secret.
What should I do if I exposed a secret API key?
Revoke or rotate the actual secret, move authenticated operations to your backend and redeploy with a server-only replacement. Remove public copies and review provider usage and billing; deleting the source alone does not revoke a leaked key.
Does this checker validate keys or inspect my account?
No. It uses local format, variable-name and limited structural rules without contacting providers. It cannot confirm validity, scopes, RLS policies, key restrictions or whether a deployment exposed a value.
Last updated