Skip to content

Are the provider keys safe in the Dapps? (doubt) #3191

Answered by zemse
bakeiro asked this question in Q&A
Discussion options

You must be logged in to vote

Actually, it's not safe at all unless there is some white-listing applied. For e.g. Alchemy allows white-listing by contract address, so "eth_call" things would only work for certain contracts and someone can't just steal your API key and plug in their app which has to work with a different contract. Also, there is a domain white-list in Alchemy, so if a request is coming from a different domain, it would give a CORS error, however, this kind of protection can be bypassed from the backend, but still, it's good to have.

If you have an API key from a service that does not provide a white-listing feature, then you should have a backend that acts as a proxy and only allow certain kind of requ…

Replies: 1 comment 4 replies

Comment options

You must be logged in to vote
4 replies
@bakeiro
Comment options

@zemse
Comment options

zemse Jul 25, 2022
Collaborator

@ricmoo
Comment options

@bakeiro
Comment options

Answer selected by bakeiro
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants