# Including passwords and/or API keys in programs

**URL:** <https://community.thunkable.com/t/including-passwords-and-or-api-keys-in-programs/23516>\
**Category:** Questions about Thunkable X\
**Created:** [April 24, 2018, 2:16pm UTC](https://community.thunkable.com/t/including-passwords-and-or-api-keys-in-programs/23516 "2018-04-24T14:16:43Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ctm](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/ctm/32/18113_2.png) [@ctm](https://community.thunkable.com/u/ctm)\
**Post date:** [April 24, 2018, 2:16pm UTC](https://community.thunkable.com/t/including-passwords-and-or-api-keys-in-programs/23516/1 "2018-04-24T14:16:43Z")

</div>

I’m curious if it’s safe to include credentials and/or API secret keys in applications. In particular, I’m using my Thunkable app to control some IoT devices and the associated cloud service requires an API secret key. I’ve hard-coded it into my app, as I don’t want the users to be aware of it. However, I’m wondering if this creates a vulnerability wherein hackers can dismantle my app and get the key.

Thoughts? If the above practice is ill-advised, please offer a suggestion on how to address the need for the secret key.

Thanks

---

<div class="post-metadata">

**Author:** ![Taifun](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/taifun/32/1547_2.png) [@Taifun](https://community.thunkable.com/u/Taifun)\
**Post date:** [April 24, 2018, 3:26pm UTC](https://community.thunkable.com/t/including-passwords-and-or-api-keys-in-programs/23516/2 "2018-04-24T15:26:36Z")

</div>

use the **obfuscate** block from the text drawer to store sensible data

Taifun

---

<div class="post-metadata">

**Author:** ![ctm](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/ctm/32/18113_2.png) [@ctm](https://community.thunkable.com/u/ctm)\
**Post date:** [April 24, 2018, 3:31pm UTC](https://community.thunkable.com/t/including-passwords-and-or-api-keys-in-programs/23516/3 "2018-04-24T15:31:13Z")

</div>

@Taifun, thanks for the suggestion. I’m using iOS and it appears that block is not yet available. Until it’s available, is it risky to include sensitive data in an app or does the obfuscate just make it a lot harder to “see”?

[update] actually, I can’t find **obfuscate** anywhere in the documentation, even for Android

---

<div class="post-metadata">

**Author:** ![Taifun](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/taifun/32/1547_2.png) [@Taifun](https://community.thunkable.com/u/Taifun)\
**Post date:** [April 24, 2018, 3:36pm UTC](https://community.thunkable.com/t/including-passwords-and-or-api-keys-in-programs/23516/4 "2018-04-24T15:36:54Z")

</div>

> [@ctm](#):
>
> I can’t find obfuscate anywhere in the documentation, even for Android

that block was added later and forgotten to add in the documentation… @thunkable  
I now changed the category of your post to #iosdiscuss  
Taifun

---

<div class="post-metadata">

**Author:** ![ctm](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/ctm/32/18113_2.png) [@ctm](https://community.thunkable.com/u/ctm)\
**Post date:** [April 24, 2018, 3:39pm UTC](https://community.thunkable.com/t/including-passwords-and-or-api-keys-in-programs/23516/5 "2018-04-24T15:39:32Z")

</div>

Actually, my app will be both for iOS and Android in the not-too-distant future, so it’s relevant to both platforms. Thanks for your assist.

---

<div class="post-metadata">

**Author:** ![arun](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/arun/32/42_2.png) [@arun](https://community.thunkable.com/u/arun)\
**Post date:** [April 24, 2018, 6:19pm UTC](https://community.thunkable.com/t/including-passwords-and-or-api-keys-in-programs/23516/6 "2018-04-24T18:19:51Z")

</div>

Thanks for catching this. We’ve added that block to our docs. We’ve also added it to our plans for Thunkable ✕

---

<div class="post-metadata">

**Author:** ![HugoCosta](https://avatars.discourse-cdn.com/v4/letter/h/b9bd4f/32.png) [@HugoCosta](https://community.thunkable.com/u/HugoCosta)\
**Post date:** [November 5, 2018, 3:50pm UTC](https://community.thunkable.com/t/including-passwords-and-or-api-keys-in-programs/23516/7 "2018-11-05T15:50:42Z")

</div>

I can’t find the obfuscate block in Thunkable X, is it still not available?

---

<div class="post-metadata">

**Author:** ![User81](https://avatars.discourse-cdn.com/v4/letter/u/ba9def/32.png) [@User81](https://community.thunkable.com/u/User81)\
**Post date:** [November 5, 2018, 4:20pm UTC](https://community.thunkable.com/t/including-passwords-and-or-api-keys-in-programs/23516/8 "2018-11-05T16:20:48Z")

</div>

no, it is not available.

I have made good experince with using firebase (Realtime DB) component. Everytime I need a API key or password, I catch it from Realtime DB

---

<div class="post-metadata">

**Author:** ![ioannis](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/ioannis/32/146956_2.png) [@ioannis](https://community.thunkable.com/u/ioannis)\
**Post date:** [November 8, 2024, 11:54am UTC](https://community.thunkable.com/t/including-passwords-and-or-api-keys-in-programs/23516/9 "2024-11-08T11:54:49Z")

</div>


