API Key Security
You control provider keys. Smart AI Comparison stores them server-side for compare requests and shows masked hints in the UI—not “keys never leave your browser.”
Keys are submitted over HTTPS to the edge function and stored under environment-prefixed KV keys. The Providers UI shows masked hints only. Full key values are not returned on GET. Rotate or delete keys from the Providers screen when needed.
- Storage: server KV (not public HTML or client-only storage for production compare)
- Transport: HTTPS to authenticated edge endpoints
- Display: masked prefixes in the UI
- Your responsibility: treat prompts as sensitive; do not paste secrets into prompts