API Key Guardian
Your AI keys are worth stealing. Keep them out of reach.
Products now call many AI models, and every call runs on an API key. API Key Guardian keeps those keys off devices and out of app code, so a leaked app never becomes a leaked bill.
REQUEST PATH
Your app
No secret keys inside
API Key Guardian
Checks the app, applies limits
AI providers & APIs
Keys used only here
Why it matters now
In the AI era, a leaked key is a running meter.
A leaked key used to expose some data. Now it can also buy AI compute on your account, around the clock, until someone notices.
Apps can be taken apart
Anything shipped inside a mobile or web app can be extracted. A key in the code is a key in public.
AI keys spend money
Every request to an AI model is billed. A leaked key lets anyone run work on your account, at your cost.
Quotas run out for real users
Abuse uses up rate limits and quotas, so the people who actually use your product get errors.
More models, more keys
Teams now use several AI providers at once. Every extra key is another thing that can leak.
What it does
A protective layer between your apps and every API.
Keys never ship in the app
Provider keys stay on the server side. The app only ever sees a short-lived, limited permission.
Only your app gets through
Requests are checked to confirm they come from your genuine app before they reach any provider.
Limits and budgets
Set usage limits per user, device or app so one bad actor can't drain your quota or your bill.
Rotate without a release
Replace or rotate a key centrally. No app update and no waiting for store review.
See unusual usage
Spot spikes and suspicious patterns early, and shut access off before they become costly.
Works across AI providers
One protective layer in front of the different AI models and APIs your products rely on.
Built in-house first
Made for the way we ship our own apps.
Like AppsKit SDK and Pentabit Insights, API Key Guardian comes from running our own portfolio of AI-powered mobile apps. It protects the keys behind them, and it is available to other teams with the same problem.
Good habits, with or without us
- Never put a provider key in app code, config files or a public repository.
- Give every key the narrowest permission and spending cap the provider allows.
- Use separate keys for development and production.
- Rotate keys on a schedule, and immediately after anyone with access leaves.
- Watch usage daily — a sudden spike is often the first sign of a leak.
