# Permanent access tokens - Public?

**URL:** <https://community.prismic.io/t/permanent-access-tokens-public/1964>\
**Category:** Developing with Prismic\
**Tags:** graphql\
**Created:** [September 23, 2020, 1:25am UTC](https://community.prismic.io/t/permanent-access-tokens-public/1964 "2020-09-23T01:25:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jason](https://dub1.discourse-cdn.com/flex013/user_avatar/community.prismic.io/jason/32/292_2.png) [@jason](https://community.prismic.io/u/jason)\
**Post date:** [September 23, 2020, 1:25am UTC](https://community.prismic.io/t/permanent-access-tokens-public/1964/1 "2020-09-23T01:25:39Z")

</div>

We were considering making GraphQL API calls on the client side, but because it requires an auth token, I'm curious about security. If we generate a "Access to master" token and use in frontend code, is that a security risk? Can those tokens be public? How do you lock them down if so? Like can you restrict it to a domain?

---

<div class="post-metadata">

**Author:** ![Pau](https://dub1.discourse-cdn.com/flex013/user_avatar/community.prismic.io/pau/32/5422_2.png) [@Pau](https://community.prismic.io/u/Pau)\
**Post date:** [September 23, 2020, 3:51am UTC](https://community.prismic.io/t/permanent-access-tokens-public/1964/2 "2020-09-23T03:51:38Z")

</div>

Hey Jason!

Publicly accessible API keys or Tokens shouldn’t be committed to your Github repo along with all other docs. The usual most common way to hide your Tokens in the front-end is by creating an .env file which is never shown in the repository.

I found this really useful article online that might help you understand this better 😉

> **[How to Hide Your API Keys](https://medium.com/better-programming/how-to-hide-your-api-keys-c2b952bc07e6)**
>
> Prevent theft by securing your API keys

---

<div class="post-metadata">

**Author:** ![Pau](https://dub1.discourse-cdn.com/flex013/user_avatar/community.prismic.io/pau/32/5422_2.png) [@Pau](https://community.prismic.io/u/Pau)\
**Post date:** [September 25, 2020, 8:03pm UTC](https://community.prismic.io/t/permanent-access-tokens-public/1964/4 "2020-09-25T20:03:39Z")

</div>

This issue has been closed due to inactivity.

---

<div class="post-metadata">

**Author:** ![system](https://dub1.discourse-cdn.com/flex013/user_avatar/community.prismic.io/system/32/1746_2.png) [@system](https://community.prismic.io/u/system)\
**Post date:** [December 9, 2021, 5:19pm UTC](https://community.prismic.io/t/permanent-access-tokens-public/1964/5 "2021-12-09T17:19:12Z")

</div>


