Security best practices
Never embed a production API key in public browser or mobile application code.
Store in environment variables
Use UNIFYUNITS_API_KEY. Never hardcode keys in source control.
Never in URLs
Always send keys in the Authorizationheader only.
Separate keys per environment
Use different keys for development, staging, and production.
Rotate without downtime
Create a new key, deploy it, verify traffic, then revoke the old key.
CORS & browser clients
Public discovery routes allow any origin. Authenticated conversion routes only allow origins listed in the deploymentALLOWED_ORIGINS setting. CORS is not a security boundary.