Keep a shared market-data API key on a server you control. Have the browser call an endpoint in your app; that endpoint authenticates with the data provider and returns only the information the interface needs. A backend proxy protects the shared credential, but it does not automatically give you permission to display or redistribute market data.
Why a key in frontend code is exposed
Anything delivered to a browser can be inspected by the person using it. A key embedded in JavaScript, HTML, a source map, or a browser request is therefore not secret—even if it is obscured, minified, or loaded from an environment variable during the build. MarketData.app warns against putting its token in an unauthenticated public website and describes its token as a secret to protect like a username and password. MarketData.app authentication guidance · MarketData.app CORS guidance
As an Amazon Associate I earn from qualifying purchases.
Put the provider call behind an app endpoint
Use a server route, serverless function, or backend-for-frontend endpoint as the boundary between the browser and the provider. Keep the provider credential in server-side configuration or a managed secret store. The browser sends its request to your app; your server validates it, calls the provider using that provider’s required authentication, and returns a limited response for the UI.
- Create an app endpoint. Define a route for the specific market-data operation the interface needs, rather than exposing a general-purpose pass-through to the provider.
- Store the credential server-side. Use server-only configuration or a secret manager. Avoid build-system variable conventions that publish values into browser bundles.
- Validate each request. Check symbols, time ranges, and other parameters on the server. Apply your own access controls and request limits so an outside caller cannot freely use your route as a proxy.
- Authenticate to the provider. Follow the selected API product’s documented method. MarketData.app recommends bearer-token authentication in a header rather than placing a token in a URL, where credentials may be stored or cached. MarketData.app authentication guidance
- Return only what the interface needs. Do not include the provider key in JSON, HTML, error messages, or other responses. Handle errors without disclosing secrets.
- Keep secrets out of logs. If a credential is exposed, revoke or rotate it promptly. MarketData.app says a compromised token should be revoked and reissued through its helpdesk. MarketData.app CORS guidance
Does CORS hide an API key?
No. CORS controls whether a browser permits a page from one origin to read a response from another origin. It does not conceal a key sent by the browser: the user can inspect the page’s code and requests. An allowlist of origins is not a safe place to store a shared credential.
#1 Best Overall
- Standard fitting for most door bolts
MarketData.app calls its CORS headers a convenience for personal browser use and local development, not a way to protect a token embedded in a public site. Its documentation states: “Never Expose Your Token on a Public Website”. MarketData.app CORS guidance
Choose authentication for the API product you use
Authentication details vary by provider and product. Do not assume that one provider’s header names or token flow apply to another API.
Rank #2
- MarketData.app: Its API uses bearer-token authentication; the provider recommends sending the token in an Authorization header. Authentication documentation
- Alpaca Trading API: Its market-data documentation describes credentials sent in the
APCA-API-KEY-IDandAPCA-API-SECRET-KEYheaders. - Alpaca Broker API: Its documentation describes exchanging client credentials for a short-lived access token. Use the flow for the API product you actually selected. Alpaca market-data documentation
Protecting the key does not settle data rights
A server-side proxy can keep a shared credential out of browser code, but it cannot determine whether your app may show, cache, export, or redistribute the data. Check the selected provider’s agreement for your audience, geography, exchange and data type, and intended use. MarketData.app says public-facing display of its data requires a commercial redistribution license under its stated terms. That is a provider-specific policy, not a universal rule for every market-data service. MarketData.app CORS and licensing guidance
Recommended Free Tools
Public app versus personal or internal use
MarketData.app distinguishes personal or internal browser use from a public product that makes its data available to visitors. Its BYOK material describes a separate, restricted model in which each user’s key stays on that user’s device and data remains within the app under the stated restrictions; it does not establish general permission for exports or onward sharing. Do not apply either policy to another provider. If the intended use is unclear, ask the provider for guidance on the current agreement. CORS and public-display terms · MarketData.app BYOK terms
Quick Recap
Best Value
Rank #4
Rank #3
If a key has already reached the browser
- Revoke or rotate the exposed key with the provider; removing it from the current page does not invalidate copies already seen.
- Move the replacement credential to server-side configuration or a managed secret store.
- Update the app so browser requests go through your validated server endpoint.
- Check deployed bundles, source maps, logs, and error responses for the old credential, and avoid logging secrets going forward.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




