4 ms·
Mobile Devs – Stop leaking your API keys: There's a better way
- palata 3y ago> This setup allows for precise auditing and control, providing clear visibility into who accesses what and when. Yay, tracking. > This adds a layer of security That is assuming that the backend (which acts as a MitM) is secure, obviously. Which is not necessarily straightforward. I stopped reading half-way through, because of a weird feeling... was that AI-generated?
- AlwaysNewb23 3y agoTracking for you and your team. So if a developer on your team goes rogue, you know when and what happened, just like how you can see who committed when and what on GitHub. Your backend is as secure as you make it. The critical point is that if designed properly, this method is better than directly storing and using API keys from within your app. I can assure you that another Software Engineer at Doppler and I wrote this blog - not AI. Feel free to ask anything. Thank you for the feedback.