Security Best Practices for Developers
Protect your API keys, database credentials, and intellectual property when selling chatbots
Hardcoded API Keys in Source Code
Impact: Buyer can extract your OpenAI, Anthropic, or other API keys and use them for unlimited requests, costing YOU money.
💰 Real Cost: $500-$5,000+ per month in stolen API usage
Embedded Database Credentials
Impact: Buyer gains full access to your database, can steal customer data, delete records, or sell access to others.
💰 Real Cost: Complete data breach + legal liability + platform ban
OAuth Secrets in Code
Impact: Buyer can impersonate your application and access user accounts on third-party services.
💰 Real Cost: Platform API bans + security violations + loss of accounts
Private Webhook URLs
Impact: Buyer can intercept notifications meant for you, potentially accessing sensitive transaction data.
💰 Real Cost: Privacy violations + potential fraud
Environment Variables Configuration
// ✅ CORRECT: config.example.js (include in sale)
module.exports = {
openai_api_key: process.env.OPENAI_API_KEY || 'YOUR_OPENAI_KEY_HERE',
database_url: process.env.DATABASE_URL || 'postgresql://user:pass@host/db',
stripe_secret: process.env.STRIPE_SECRET_KEY || 'sk_test_...',
webhook_secret: process.env.WEBHOOK_SECRET || 'whsec_...'
};
// Buyer creates their own .env file:
OPENAI_API_KEY=sk-buyer-key-12345
DATABASE_URL=postgresql://buyer-db-url
STRIPE_SECRET_KEY=sk-buyer-stripe-keyWhy this works: Buyer MUST use their own credentials. You never expose yours.
Separate Configuration File
// ✅ CORRECT: Include empty config template
// config.template.js (rename to config.js and fill in)
export default {
apiKey: "", // Get from: https://platform.openai.com/api-keys
databaseUrl: "", // Your PostgreSQL connection string
stripeKey: "", // Your Stripe secret key
webhookUrl: "" // Your webhook endpoint
};
// Add to .gitignore:
config.js
.env
secrets/Why this works: Template shows structure; buyer provides actual values.
Setup Instructions Document
# 🔐 SETUP INSTRUCTIONS FOR BUYER
## Required API Keys (You Must Obtain):
1. **OpenAI API Key** ($18/1M tokens)
- Sign up: https://platform.openai.com/signup
- Get key: https://platform.openai.com/api-keys
- Add to .env: OPENAI_API_KEY=sk-...
2. **Database** (Free tier available)
- Use: Supabase, Railway, or AWS RDS
- Get connection string
- Add to .env: DATABASE_URL=postgresql://...
3. **Stripe Account** (For payments)
- Sign up: https://dashboard.stripe.com/register
- Get secret key from dashboard
- Add to .env: STRIPE_SECRET_KEY=sk_...
## Installation:
1. Copy .env.example to .env
2. Fill in YOUR API keys above
3. Run: npm install
4. Run: npm startWhy this works: Clear documentation prevents support requests and ensures buyer understands they need their own services.
How It Works:
Instead of giving buyers your API keys, you provide a proxy endpoint they call, which authenticates them and forwards requests to OpenAI using YOUR key.
┌─────────────┐ ┌──────────────────┐ ┌───────────┐
│ Buyer's │ │ Your Proxy API │ │ OpenAI │
│ Chatbot │────────>│ (License Auth) │────────>│ API │
│ │ Token │ checks license │ Your │ │
└─────────────┘ └──────────────────┘ Key └───────────┘
│
▼
Usage Tracking DB
(meters per license)Benefits:
- Buyer never sees your API key
- You track/limit usage per license
- You can revoke access if license violated
- Monetize via usage-based pricing
Complete this checklist BEFORE submitting your chatbot for approval:
Legal Protection via Licensing Terms
Every purchase includes enforceable license agreements prohibiting unauthorized key usage, redistribution, or credential theft. Violations = immediate account ban + legal action.
Escrow Protection Prevents Premature Access
Buyers cannot access source code until payment clears and is held in escrow, reducing "purchase and chargeback" fraud attempts.
Complaint System for Key Theft
If you detect unauthorized key usage, file a complaint. We investigate, and proven violations result in buyer account suspension and potential refund/reimbursement.
Mandatory Security Review
Our approval team checks for hardcoded credentials during bot submission. Bots with exposed keys are rejected until fixed.