UnifyUnitsDevelopers

Security best practices

Never embed a production API key in public browser or mobile application code.

Store in environment variables

Use UNIFYUNITS_API_KEY. Never hardcode keys in source control.

Never in URLs

Always send keys in the Authorizationheader only.

Separate keys per environment

Use different keys for development, staging, and production.

Rotate without downtime

Create a new key, deploy it, verify traffic, then revoke the old key.

CORS & browser clients

Public discovery routes allow any origin. Authenticated conversion routes only allow origins listed in the deploymentALLOWED_ORIGINS setting. CORS is not a security boundary.