API · 40 min
Secrets stay server-side
- Keep XAI_API_KEY out of git, the browser, and this LMS
- Know how to rotate a leaked key
The common “hello world” on the internet pastes the key into a React file “just to see it work.” That file is then committed, or deployed, or copied into a lesson artifact. Bots harvest `xai-` and `sk-` strings from GitHub in minutes.