AI Engineering Program — go from software engineer to production AI engineer · Live training with Kirill Eremenko · Watch the program breakdown→AI Engineering Program — go from software engineer to production AI engineer · Live training with Kirill Eremenko · Watch the program breakdown→AI Engineering Program — go from software engineer to production AI engineer · Live training with Kirill Eremenko · Watch the program breakdown→

Q: How do I handle API keys and secrets when deploying an AI app?

Rule one: secrets never go in your code. Rule two: secrets never go in your Git repository. Most painful beginner mistakes in AI deployment come down to breaking one of these.

The standard pattern locally: keep secrets in a .env file (your API keys, one per line), load them in code as environment variables, and add .env to your .gitignore file so Git never tracks it. Your code then reads the key by name and contains no secret itself.

When you deploy, the .env file SHOULD NOT travel with the code. Instead, every platform has its own place to store secrets: Hugging Face Spaces has a Secrets section, Render has environment variable settings, AWS has Secrets Manager. You paste the key into the platform once, and your deployed code reads it the same way it did locally.

Why so strict? Because public repositories are scanned by bots around the clock, and a key committed to GitHub is typically found and abused within minutes, at your expense. Deployment platforms that build from public repositories expose everything in them, including files you forgot about.

If a key ever does leak: revoke it immediately in the provider's dashboard and issue a new one. Rotating a key takes one minute. The bill from a stolen one doesn't.

← Back to the full FAQ