Skip to content

Secrets

Encrypted settings, like API keys, that only your Base44 backend can read, so they never end up in the browser.

Also called environment variables.

Anything in your frontend code is public. Open dev tools and it's right there. So an API key sitting in a page component belongs to whoever finds it first.

Secrets live in the dashboard, or base44 secrets set if you use the CLI. A backend function reads one like this:

ts
const key = Deno.env.get('STRIPE_SECRET_KEY');

The pattern never changes. The page calls your function. The function reads the secret, calls the other service and sends back only the result. The key never leaves the server.

If Base44's security scan flags an exposed secret, moving it isn't enough. Assume it leaked, rotate it with the provider, then store the new one properly.