No. Any key present in JavaScript that runs in the browser can be extracted from the page source, network tab or memory, no matter how it is obfuscated. Call the LLM from a small server or edge function and have your game talk to that instead.
At a glance
| Fact | Value | Source |
|---|---|---|
| Client-side API keys are extractable | always readable | strac.io |
| Where to store keys instead | env vars, secrets store | support.google.com |
| Committed keys get flagged in git history | secret scanning | docs.github.com |
No. A key placed anywhere in the JavaScript your browser game ships – inline, in a bundled .js file, or fetched into memory at runtime – can be read by any player who opens dev tools, views page source, or inspects the network tab. Obfuscation and minification don’t fix this: “to ensure the security of your API keys, never embed them in URLs or client-side code”.
For AI coding workflows, the Playgama MCP server lets agents upload builds and publish a sandbox.
The fix is a thin backend: your game sends a request to a server or edge function you control (a Cloudflare Worker, a small Node service, a serverless function), and that server holds the real key and calls the LLM. Cloudflare Workers, for example, store such credentials as encrypted secrets rather than plain config values. OpenAI’s own SDK explicitly warns that its browser-allowed mode “exposes your secret API credentials in the client-side code” – it exists for prototyping, not shipping. Google gives the same guidance for its own API keys: store them in environment variables or files outside your source tree, never embedded in the app.
Watch for the key leaking into your git history even if it never appears in the shipped bundle – GitHub’s secret scanning exists specifically because committed keys become targets.
Sources
- Best practices for securely using API keys – API Console Help
- The Comprehensive Guide to Sharing and Storing API Keys Securely
- About secret scanning – GitHub Docs
- GitHub – openai/openai-node
- Secrets – Cloudflare Workers docs
- Playgama Bridge SDK docs
Related questions
What if I only use the LLM key during development, never in the shipped build?
Still keep it out of files that get committed. Use a local .env file excluded from git, or your terminal’s environment variables, and load it server-side only.
Can I hide the key by loading it from a separate JSON file instead of hardcoding it?
No, a fetched JSON file is just as readable in the network tab as an inline string. Only a server that never sends the key to the browser is safe.
Does putting my game behind an iframe on a portal protect the key?
No. The iframe still runs your JavaScript in the player’s browser, so any key inside it is exposed the same way as on your own site.
Last updated: 30 September 2026