Security
Keep keys only in trusted backend secret storage or secure local configuration. Use a separate key per application, set quota, expiration, model and IP restrictions, rotate long-lived keys, and revoke a key immediately when a device or client is no longer trusted.
Do not call Sprelay directly from a frontend
The safe architecture is:
User interface -> your backend (authentication and rate limits) -> Sprelay APIThe arrows show the only permitted request direction. Your backend stores the key and enforces per-user limits; the browser never receives the key.
Minimize logs
Log only what troubleshooting needs: time, model, status, latency, usage, and request ID. Redact Authorization, x-api-key, x-goog-api-key, prompts, uploaded documents, email, payment data, and private tool results.
Tool execution
Model output is untrusted input. Enforce an allowlist, JSON Schema validation, business authorization, timeouts, audit logs, and user confirmation or idempotency for risky writes.
Before using a third-party client, determine whether it stores the key locally or syncs it to another server. When uncertain, use a dedicated low-quota, model-restricted key.
If a leak is suspected, revoke first and investigate second. Follow API Key Security for the full rotation process.
