Pre-built code blocks

An API key that never reaches the browser

Your API key or each customer's own key, used from your server without ever reaching a browser

For when the answer to “It calls an AI or a paid API with a secret key” is yes.

In SaaS, BYOK or "bring your own key" means each CUSTOMER supplies a provider key and your app holds it in custody.

A key sealed in a safe behind a tall wall, with a single valved pipe running through the wall to a plain empty window on the other side

Skip the rebuild

You do not write this one. It arrives in your project as ordinary source you can read, change and keep, with its audit record and its caveats beside it.

  1. Download the Playground. It is free and runs on your own machine.
  2. Start a new app and tick “It calls an AI or a paid API with a secret key”.
  3. This block is written in, along with anything else you ticked.

Download the Playground See the other blocks

The mistake it removes

Two failures, both quiet until they are expensive. A key that reaches the client is public the moment the bundle ships and can only be rotated, never hidden — and it is not just a bundle: a config endpoint, a source map, or an error body echoed from the provider will all do it. And an unbounded call loop against a metered API is a bill with no ceiling, which arrives overnight and is nobody's fault by morning.

What is already handled

Each of these was checked by running the code, not by reading it.

What you still have to do

A copied file cannot own your secrets, your host or your legal obligations. This is the part the block deliberately does not claim.

What lands in your project

node

  • node/byok.js
  • node/vault.js

callApi(): the key read server-side only, a hard timeout, a bounded retry, per-caller rate limiting, a spend ceiling that RESERVES before the call and settles after it, a startup refusal on any unusable setting, and redact() over every log and error. Pass { vault, tenantId } to spend that customer's stored key instead of API_KEY. createKeyVault({ store, master }) in vault.js: put, use, revoke, rotateMaster, list. Plus wrapUntrusted() for the model case.

What you supply

Licensed MIT. It is a starting point, not a finished product.

Get it

Download the Playground See the other blocks

Nothing here is locked. The files are yours, in your folder, under a permissive license.

Questions

Is An API key that never reaches the browser audited?
No. No full audit has been run against this block yet, which is not the same as a pass. What is verified about it is listed on this page, and what is not is listed beside it.
What do I still have to do myself?
Your own authenticated caller id, passed to the rate limiter. This block has no user model, and BYOK_RATE_PER_MIN keyed on anything a caller can write (a header, a query param) is not a limit at all.
How do I get this code?
Download the Playground, start a new app, and tick “It calls an AI or a paid API with a secret key”. The block is written into your project as ordinary source you can read and edit.

All pre-built code blocks · Learn to build from zero · The coding guide