Dashboard
0%
1
Curious builder0 XP earned · 300 to level 2
0 daysFinish a lesson to begin
Badge collection0 of 6 unlocked
51 small wins to finish your pathNext question →

Q9EasyConcept

How should API keys and secrets be managed in LLM applications?

30-second answerSay your answer out loud first, then reveal.

Checklist

  1. No secrets in frontend code. Browser and mobile apps call your backend, which holds the keys. (For bring-your-own-key products, store user keys encrypted and keep them server-side or in secure client storage, never logged.)
  2. Secrets manager + IAM: workloads authenticate with identities (e.g. workload identity), not long-lived keys where possible.
  3. Per-service keys with spend limits, so a compromised key has a bounded blast radius.
  4. Gateway: applications never see provider keys; the gateway holds them.
  5. Rotation: automated rotation; immediate revocation playbook.
  6. Detection: secret scanning in CI and git history; alerts on unusual token usage (a leaked key often shows up as a cost spike).
  7. Never put secrets in prompts: models can be manipulated into revealing system prompts.

This is what real progress feels like.