Can I keep my API keys in the code while I build?

Updated October 2026 · How we answer

Short answerKeep keys out of source files from the start. Store them in environment variables or a secrets manager, and make sure the file that holds them is excluded from version control.

Where secrets belong

Code gets copied, pasted, shared and sometimes published by accident. A key written into a source file can end up in a screenshot, a chat log or a public repository. Environment variables keep the value out of the code while still letting the app use it.

AI tools often generate code with placeholders or sample keys. Look for real values hidden in the output before you save the file, and replace them with a reference to an environment variable.

Checking what you have pushed

Add your local environment file to the ignore list before the first commit. If a key does reach version control, treat it as exposed: rotate it in the provider's dashboard and remove it from history. Deleting the line in a new commit is not enough.

Use a secret scanning tool or a pre-commit check if your platform offers one. These catch many accidental leaks before they leave your machine.

  • Store keys in environment variables.
  • Add local env files to the ignore list.
  • Rotate any key that was ever committed.
  • Enable secret scanning if your platform offers it.

Common mistakes

  • Deleting a leaked key from the latest commit but leaving it in the history.
  • Trusting that a private repository is always safe for live keys.
From our shopsSwiftCase: Curated phone cases that ship in 48 hours.