<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are there any protections for hosting the client side API key on github? in ArcGIS JavaScript Maps SDK Questions</title>
    <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/are-there-any-protections-for-hosting-the-client/m-p/1105885#M74912</link>
    <description>&lt;P&gt;It's a good question&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/513220"&gt;@gggg&lt;/a&gt;. Here is our official documentation on the subject:&lt;/P&gt;&lt;P&gt;&lt;A href="https://developers.arcgis.com/documentation/mapping-apis-and-services/security/security-best-practices/#api-key-security" target="_blank"&gt;https://developers.arcgis.com/documentation/mapping-apis-and-services/security/security-best-practices/#api-key-security&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In short, it's a good idea to limit your API key to consume only the services you require, and use the allowed referrer to limit usage to your app's URL. Also, you should monitor the API key's usage, and delete it when you're done, and/or rotate your API key as needed.&lt;/P&gt;</description>
    <pubDate>Fri, 08 Oct 2021 13:47:52 GMT</pubDate>
    <dc:creator>Noah-Sager</dc:creator>
    <dc:date>2021-10-08T13:47:52Z</dc:date>
    <item>
      <title>Are there any protections for hosting the client side API key on github?</title>
      <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/are-there-any-protections-for-hosting-the-client/m-p/1105404#M74899</link>
      <description>&lt;P&gt;I need to host my client side API key on github pages to share my project. except the API key will be publicly shown in the source code since it is a client side API key. Does ESRI have any protections for this case?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 01:01:54 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/are-there-any-protections-for-hosting-the-client/m-p/1105404#M74899</guid>
      <dc:creator>gggg</dc:creator>
      <dc:date>2021-10-07T01:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: Are there any protections for hosting the client side API key on github?</title>
      <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/are-there-any-protections-for-hosting-the-client/m-p/1105885#M74912</link>
      <description>&lt;P&gt;It's a good question&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/513220"&gt;@gggg&lt;/a&gt;. Here is our official documentation on the subject:&lt;/P&gt;&lt;P&gt;&lt;A href="https://developers.arcgis.com/documentation/mapping-apis-and-services/security/security-best-practices/#api-key-security" target="_blank"&gt;https://developers.arcgis.com/documentation/mapping-apis-and-services/security/security-best-practices/#api-key-security&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In short, it's a good idea to limit your API key to consume only the services you require, and use the allowed referrer to limit usage to your app's URL. Also, you should monitor the API key's usage, and delete it when you're done, and/or rotate your API key as needed.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 13:47:52 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/are-there-any-protections-for-hosting-the-client/m-p/1105885#M74912</guid>
      <dc:creator>Noah-Sager</dc:creator>
      <dc:date>2021-10-08T13:47:52Z</dc:date>
    </item>
  </channel>
</rss>

