Keep secrets on the server
Use environment variables or a secret manager and limit key permissions. Never put provider keys in client-side code, screenshots, repositories, or query strings.
Keep provider credentials under your control. BYOK is a documentation concept here, not an implemented key vault.
Use environment variables or a secret manager and limit key permissions. Never put provider keys in client-side code, screenshots, repositories, or query strings.
This site does not ask you to upload a provider key. Sign in with Google only if you want to explore the account and test subscription flow.
Preview only · No live API access · Test payments only