Move your AI API key out of browser code into a server function, rotate the exposed key, and keep your app's AI feature working.
My OpenAI key is in my frontend code. Move it somewhere safe
How it works
- Prove the key is exposed: Vovy opens your live site, checks the browser's network and source files, and shows you the key sitting there for anyone to copy.
- Create a server function: Vovy asks Claude Code to make a Supabase Edge Function that takes the user's message, calls the AI with the secret key, and returns the reply.
- Require a signed-in user: Claude Code makes the function check the user's session, so strangers cannot use your endpoint as a free AI proxy.
- Point the frontend at it: Claude Code replaces direct AI calls with calls to your function and deletes the key from frontend code and .env files with public prefixes.
- Rotate the old key: The old key was public, so Vovy creates a new one, stores it as a Supabase secret, and deletes the old one. Deleting a key is irreversible, so it asks.
What you provide
- Your app's code
- A Supabase project
- Access to your AI provider account
What you get
- A server function holding the key
- Only signed-in users can call it
- The leaked key revoked
FAQ
Is it really that bad if the key is in my frontend?
Yes. Anyone can open dev tools, copy it, and run up your bill. Bots scan for keys like this.
Can I use Vercel instead of Supabase?
Yes. A Vercel serverless function works the same way. Vovy uses whichever backend you already have.
Will this slow my app down?
Barely. It adds one short hop to your server, usually far less time than the AI itself takes.
Related tasks
All tasks