Skip to content
All writing
Engineering22 Aug 20263 min read

Never accept a client secret through a web form

An agency that stores its clients' API keys has built a single point of failure for every client at once.

Every project needs access to accounts the client owns — analytics, DNS, a payment gateway, a shipping provider. The default approach is a form: paste the key here, we will keep it safe. It is convenient, and it is a bad idea.

The problem is aggregation. One agency database holding twenty clients' payment gateway keys is a far more attractive target than any one of those clients, and the blast radius of a single mistake is every client simultaneously. Nothing about running a studio makes us qualified to hold that.

So we built the handover tool around a fork. Every field is marked either public or secret. A public value — a GA4 property ID, a domain, a profile URL — gets a real input, is stored, and is visible to the team. A secret value gets no input at all. Instead the page explains, with screenshots, how to add us as a user on the client's own account.

The result is that our database contains nothing worth stealing, and the client keeps ownership throughout rather than receiving it back at the end. Removing our access at handover becomes a two-minute job on their side instead of a promise on ours.

It is slightly more work to set up and considerably less work to worry about.

Written by the Valentir team. If you want to argue with any of it, that is what hello@valentir.in is for.

Taking new projects

Tell us what you are trying to build.

Bring a rough idea or a finished spec. Either way you get a straight answer about scope, cost and whether we are the right studio for it — and if we are not, usually a pointer to who is.

24h
Reply to every enquiry
24h
Proposal after the call
₹0
Cost of the first conversation