Keep secrets out of browser bundles
Treat every value shipped to the browser as public. Vite exposes variables with its configured public prefix, including VITE_ by default, in client code. Keep private credentials on the server or in the deployment secret store, use minimal permissions, and never print them in build logs. If a credential leaks, revoke or rotate it; deleting the file does not remove repository history.
#testing#shipping
Sources
Verified 2026-09-30