AntiPattern
Client-Side API Key Leakage
client-side-api-key-leakage
API keys treated as client-embedded credentials get exposed because HTTPS protects transport but not device-side observability, proxies, or request replay, enabling attackers to resend bearer requests to OpenAI endpoints and impersonate your app.