Keep the API key secret
Updated 1 October 2026 · BugsRadar team
A project has two API keys, primary and secondary, and either one sends errors to the project's channels. Treat each key like a database password: it belongs only in code that runs on your own servers.
Where the key may go
- Use it in back ends and APIs, worker services, scheduled jobs, CI/CD pipelines and scripts on your servers.
- Never put it where other people can see it: in a browser app (React, Angular, Vue or any JavaScript that reaches the browser), in a mobile or desktop app you ship to customers or users, or in a public repository. Anyone can take the key out of such code.
- Keep it in configuration, an environment variable or the secrets of your CI system, not in the source.
What a key can do
Whoever has the key can fill your channels with messages, but can't read anything or change settings.
If a key leaks
Move your applications and scripts to the project's other key, then press Regenerate next to the leaked key on the project's page in the web app. The leaked key stops working at once, and your apps keep reporting through the other one.
Which project does a key belong to?
Not sure which key an application uses? The Check API Key page of the web app shows which of your projects a key belongs to.
Next: Rules →