# My security and API keys

**URL:** https://community.thunkable.com/t/my-security-and-api-keys/1311834
**Category:** Questions about Thunkable X
**Created:** [May 27, 2021, 8:05pm UTC](https://community.thunkable.com/t/my-security-and-api-keys/1311834 "2021-05-27T20:05:49Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![gene.arnold9d](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/gene.arnold9d/32/86268_2.png) [@gene.arnold9d](https://community.thunkable.com/u/gene.arnold9d)
#### Post date: [May 27, 2021, 8:05pm UTC](https://community.thunkable.com/t/my-security-and-api-keys/1311834/1 "2021-05-27T20:05:49Z")

</div>

I’ve tried to find this information but have not been successful. If I create a public app are all my app settings shared with the person that makes a copy of it? I realize that any of my REST endpoints are exposed in the project so that would mean that if I include any private header information that is now exposed but what about the actual app settings like my Firebase information? I see Thunkable Pro in my very near future but I was hoping I still had a little time.

---

<div class="post-metadata">

### Author: ![jane](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/jane/32/27575_2.png) [@jane](https://community.thunkable.com/u/jane)
#### Post date: [May 28, 2021, 7:23am UTC](https://community.thunkable.com/t/my-security-and-api-keys/1311834/2 "2021-05-28T07:23:20Z")

</div>

Hi there,

Project settings such as Firebase API details will be hidden.

This is what people will see if they click on your project and don’t remix it:

 ![Screen Shot 2021-05-28 at 8.22.01 AM](https://us1.discourse-cdn.com/flex015/uploads/thunkable/original/3X/b/1/b1b95ea31610bd424e8b7920d798f7184a5a98de.png)

And this is what people will see if they remix your project:

 ![Screen Shot 2021-05-28 at 8.22.25 AM](https://us1.discourse-cdn.com/flex015/uploads/thunkable/original/3X/2/b/2b87472a561b3277158d29f661bd04c0bfb5bcca.png)

---

<div class="post-metadata">

### Author: ![catsarisky](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/catsarisky/32/100661_2.png) [@catsarisky](https://community.thunkable.com/u/catsarisky)
#### Post date: [May 28, 2021, 11:35am UTC](https://community.thunkable.com/t/my-security-and-api-keys/1311834/3 "2021-05-28T11:35:14Z")

</div>

If you’re worried about API keys and REST endpoints with authentication in the blocks (not in the designer view), consider storing the sensitive information in firebase perhaps? (And then secure your firebase with a rule!)

---

<div class="post-metadata">

### Author: ![ioannis](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/ioannis/32/146956_2.png) [@ioannis](https://community.thunkable.com/u/ioannis)
#### Post date: [November 8, 2024, 1:22pm UTC](https://community.thunkable.com/t/my-security-and-api-keys/1311834/4 "2024-11-08T13:22:12Z")

</div>


