> ## Documentation Index
> Fetch the complete documentation index at: https://docs.avraapi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# API key safety

> Protect AvraAPI project credentials through server-only storage, environment separation, rotation, and incident response.

Your AvraAPI Client Secret authorizes server-to-server access for a project environment. Treat it with the same care as a database password or payment-provider secret.

## Safe storage checklist

* Keep Client ID and Client Secret in server-side environment configuration or a managed secret store.
* Use a different credential for Development and Production.
* Restrict secret-store access to the service that makes AvraAPI requests.
* Use HTTPS for every request.
* Keep secrets out of browser code, mobile applications, repositories, CI output, screenshots, URLs, analytics, and error reports.

## If a secret may be exposed

<Steps>
  <Step title="Rotate the credential">
    Generate a replacement from the project dashboard immediately. The old secret must be considered unsafe.
  </Step>

  <Step title="Deploy the replacement safely">
    Update your server-side configuration and restart or reload the affected service. Confirm the new credential works in the intended environment.
  </Step>

  <Step title="Investigate your delivery path">
    Remove the secret from logs, commits, CI output, browser bundles, and shared messages. Revoke exposed deploy artifacts if necessary.
  </Step>
</Steps>

## UPG additional boundary

UPG uses two separate secret classes:

| Secret | Where it belongs |
| - | - |
| AvraAPI project Client Secret | Your backend |
| Gateway provider credential | Project Gateway Vault, encrypted and never returned to the browser |

Do not copy a gateway secret into your application's `.env` file simply because it was configured in AvraAPI. UPG is designed specifically to avoid that duplication.

<Warning>
  An API key visible in a browser network tab is already an incident. Browser code may receive a public checkout session, never an AvraAPI Client Secret.
</Warning>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.