-
AI
Call the OpenAI API from the browser without leaking your key
How to call the OpenAI API and other LLM APIs from a web app without exposing your key: a server route, streaming, cost limits and a gateway.
6 min read Read -
No-code
Calling APIs from no-code tools: Webflow, Bubble and Framer
Why API calls fail with CORS errors in no-code tools, which calls run in the browser and which on a server, and how to keep API keys out of your published site.
6 min read Read -
API keys
Publishable API keys: designing keys that are safe in a browser
What makes a publishable API key safe to ship in a browser bundle: scoped capabilities, origin allowlists and their limits, quotas, test keys and rotation.
7 min read Read -
Security
Signed URLs explained: HMAC signatures, expiry and replay protection
How signed URLs work: HMAC signatures, canonical forms, expiry, method binding, nonces and replay protection, with working signing and verification code.
6 min read Read -
API keys
You can't hide an API key in frontend code. Do this instead
Why environment variables, bundlers and obfuscation can't hide an API key in frontend code, and the three patterns that actually keep secrets off the client.
6 min read Read