# Keep secrets out of browser bundles
URL: https://wwadd.dev/moves/testing-shipping/keep-secrets-server-side

Treat every value shipped to the browser as public. Vite exposes variables with its configured public prefix, including VITE_ by default, in client code. Keep private credentials on the server or in the deployment secret store, use minimal permissions, and never print them in build logs. If a credential leaks, revoke or rotate it; deleting the file does not remove repository history.

Verified: 2026-09-30

Source: [Official guidance](https://vite.dev/guide/env-and-mode)

