Install Chatbots4Sale

Add to your home screen for quick access. Works offline!

Security Best Practices for Developers

Protect your API keys, database credentials, and intellectual property when selling chatbots

Critical Security Risks

Hardcoded API Keys in Source Code

CRITICAL

Impact: Buyer can extract your OpenAI, Anthropic, or other API keys and use them for unlimited requests, costing YOU money.

💰 Real Cost: $500-$5,000+ per month in stolen API usage

Embedded Database Credentials

CRITICAL

Impact: Buyer gains full access to your database, can steal customer data, delete records, or sell access to others.

💰 Real Cost: Complete data breach + legal liability + platform ban

OAuth Secrets in Code

HIGH

Impact: Buyer can impersonate your application and access user accounts on third-party services.

💰 Real Cost: Platform API bans + security violations + loss of accounts

Private Webhook URLs

MEDIUM

Impact: Buyer can intercept notifications meant for you, potentially accessing sensitive transaction data.

💰 Real Cost: Privacy violations + potential fraud

✅ Correct Implementation vs ❌ Common Mistakes

Environment Variables Configuration

// ✅ CORRECT: config.example.js (include in sale)
module.exports = {
  openai_api_key: process.env.OPENAI_API_KEY || 'YOUR_OPENAI_KEY_HERE',
  database_url: process.env.DATABASE_URL || 'postgresql://user:pass@host/db',
  stripe_secret: process.env.STRIPE_SECRET_KEY || 'sk_test_...',
  webhook_secret: process.env.WEBHOOK_SECRET || 'whsec_...'
};

// Buyer creates their own .env file:
OPENAI_API_KEY=sk-buyer-key-12345
DATABASE_URL=postgresql://buyer-db-url
STRIPE_SECRET_KEY=sk-buyer-stripe-key

Why this works: Buyer MUST use their own credentials. You never expose yours.

Separate Configuration File

// ✅ CORRECT: Include empty config template
// config.template.js (rename to config.js and fill in)
export default {
  apiKey: "", // Get from: https://platform.openai.com/api-keys
  databaseUrl: "", // Your PostgreSQL connection string
  stripeKey: "", // Your Stripe secret key
  webhookUrl: "" // Your webhook endpoint
};

// Add to .gitignore:
config.js
.env
secrets/

Why this works: Template shows structure; buyer provides actual values.

Setup Instructions Document

# 🔐 SETUP INSTRUCTIONS FOR BUYER

## Required API Keys (You Must Obtain):

1. **OpenAI API Key** ($18/1M tokens)
   - Sign up: https://platform.openai.com/signup
   - Get key: https://platform.openai.com/api-keys
   - Add to .env: OPENAI_API_KEY=sk-...

2. **Database** (Free tier available)
   - Use: Supabase, Railway, or AWS RDS
   - Get connection string
   - Add to .env: DATABASE_URL=postgresql://...

3. **Stripe Account** (For payments)
   - Sign up: https://dashboard.stripe.com/register
   - Get secret key from dashboard
   - Add to .env: STRIPE_SECRET_KEY=sk_...

## Installation:
1. Copy .env.example to .env
2. Fill in YOUR API keys above
3. Run: npm install
4. Run: npm start

Why this works: Clear documentation prevents support requests and ensures buyer understands they need their own services.

Advanced: API Key Proxy Service (Coming Soon)

How It Works:

Instead of giving buyers your API keys, you provide a proxy endpoint they call, which authenticates them and forwards requests to OpenAI using YOUR key.


┌─────────────┐         ┌──────────────────┐         ┌───────────┐
│   Buyer's   │         │  Your Proxy API  │         │  OpenAI   │
│   Chatbot   │────────>│  (License Auth)  │────────>│    API    │
│             │  Token  │  checks license  │  Your   │           │
└─────────────┘         └──────────────────┘   Key   └───────────┘
                                │
                                ▼
                        Usage Tracking DB
                        (meters per license)

Benefits:

  • Buyer never sees your API key
  • You track/limit usage per license
  • You can revoke access if license violated
  • Monetize via usage-based pricing
Pre-Submission Security Checklist

Complete this checklist BEFORE submitting your chatbot for approval:

Never hardcode API keys in source code
REQUIRED
Use environment variables for ALL secrets
REQUIRED
Include .env.example template (not actual .env)
REQUIRED
Add setup instructions document
REQUIRED
List required services buyer must sign up for
REQUIRED
Test delivery with fresh environment to verify no secrets leak
REQUIRED
Use .gitignore to exclude config files
REQUIRED
Document estimated monthly costs for third-party APIs
RECOMMENDED
Provide cost optimization tips
RECOMMENDED
Offer setup assistance as add-on service
RECOMMENDED
What Chatbots4Sale Does to Protect You

Legal Protection via Licensing Terms

Every purchase includes enforceable license agreements prohibiting unauthorized key usage, redistribution, or credential theft. Violations = immediate account ban + legal action.

Escrow Protection Prevents Premature Access

Buyers cannot access source code until payment clears and is held in escrow, reducing "purchase and chargeback" fraud attempts.

Complaint System for Key Theft

If you detect unauthorized key usage, file a complaint. We investigate, and proven violations result in buyer account suspension and potential refund/reimbursement.

Mandatory Security Review

Our approval team checks for hardcoded credentials during bot submission. Bots with exposed keys are rejected until fixed.

Ready to List Securely?

Follow this guide, complete the checklist, and protect your business. Questions? Contact our developer support team before submitting.