Bring your own API keys in mobileCoder
Real apps often need outside services for email, payments, maps, or data. mobileCoder lets you bring your own API keys through the Secrets panel, so you stay in control of the accounts.
What bring your own keys means
Many useful features rely on an outside service. Sending email, taking a payment, showing a map, or pulling data from another product usually means calling that service through an API, and that call needs a key that proves the request is allowed.
Bring your own keys means you use your own accounts with those services. You create the account, you hold the key, and you keep the billing relationship. mobileCoder does not stand between you and the provider. The agent uses the key you supply to build the feature you asked for.
Add keys in the Secrets panel
Keys live in the Secrets panel rather than being pasted into the middle of your app where they are easy to expose. You add a key there and give it a name, then the app can use it.
- Create the key in the provider's own dashboard, such as an email or payment service.
- Add it in the Secrets panel with a clear name so you know what it is for.
- Ask the agent to use that service, and it wires the feature up using the stored key.
Keeping keys in one clearly labeled place also makes them easier to rotate or remove later.
Why this keeps you in control
Using your own keys has real advantages beyond convenience.
- You own the accounts with each provider, so your data and history stay with you.
- You control billing directly with each service rather than through a middle layer.
- You can revoke access at any time from the provider's dashboard if you need to.
- You choose the providers that fit your needs instead of being limited to a fixed set.
This is a more honest arrangement. The services are yours, and you can leave or switch without untangling someone else's setup.
Handle keys carefully
API keys are sensitive. Anyone who has a key can act as you with that service, so treat keys with care.
- Keep keys in the Secrets panel, not pasted into visible parts of the app or shared in messages.
- Use test keys while building when a provider offers a test or sandbox mode, and switch to live keys only when ready.
- Rotate a key if you think it has been exposed, and remove keys you no longer use.
- Give a key only the access it needs when the provider lets you set that.
These habits are simple and they prevent the most common mistakes.
Test the connection before you rely on it
Connecting a service is a point where things can quietly go wrong, so test it deliberately. AI generated code can be wrong, and outside services have their own rules and limits.
- Send a test request and confirm you get the result you expect from the provider.
- Check the error cases, such as a wrong key, a rejected payment, or a service that is slow to respond.
- Read the provider's documentation on limits and test modes so you are not surprised in production.
Review the code the agent wrote for the connection as well. Once it works and you have tested it, you can build on top of it with confidence.
Frequently asked questions
What does bring your own API keys mean?
Where do I put my keys?
Why use my own keys instead of a shared setup?
How should I keep keys safe?
Do I need to test a service after connecting it?
Build your idea in the browser
Describe what you want and watch it come together. No setup, nothing to install.
Open mobileCoder