-
AI
Call the OpenAI API from the browser without leaking your key
How to call the OpenAI API and other LLM APIs from a web app without exposing your key: a server route, streaming, cost limits and a gateway.
6 min read Read -
CORS
CORS with credentials: cookies, credentials: 'include' and the wildcard
Why cross-origin cookies need credentials: 'include', Access-Control-Allow-Credentials and an exact origin, how SameSite affects them, and why Vary matters.
5 min read Read -
CORS
CORS, CSP, CORP and COEP compared: browser security headers
CORS, CSP, CORP, COEP and COOP each answer a different question. Learn who sends each header, what it protects, and how they interact when a request fails.
5 min read Read -
API keys
Publishable API keys: designing keys that are safe in a browser
What makes a publishable API key safe to ship in a browser bundle: scoped capabilities, origin allowlists and their limits, quotas, test keys and rotation.
7 min read Read -
Security
Signed URLs explained: HMAC signatures, expiry and replay protection
How signed URLs work: HMAC signatures, canonical forms, expiry, method binding, nonces and replay protection, with working signing and verification code.
6 min read Read -
Security
SSRF explained: why every proxy needs a guard against internal IPs
What server-side request forgery is, how attackers reach internal services and cloud metadata through URL fetchers, and the defenses that actually hold up.
6 min read Read -
Edge
WebAssembly at the edge: transform API traffic without a server
How WebAssembly modules can rewrite API requests and responses inline: sandboxing, a minimal ABI, time and memory budgets, and choosing fail-open or fail-closed.
5 min read Read -
WebSockets
WebSockets and CORS: what the browser checks and how to proxy them
CORS does not apply to WebSockets. Learn what the Origin header does, how servers must check it, how to authenticate a socket, and how to proxy one safely.
5 min read Read -
API keys
You can't hide an API key in frontend code. Do this instead
Why environment variables, bundlers and obfuscation can't hide an API key in frontend code, and the three patterns that actually keep secrets off the client.
6 min read Read