# How Personal APIMart API Keys Are Handled for GPT-Image2 Generation in awesome-gpt-image-2

> Learn how awesome-gpt-image-2 securely handles personal APIMart API keys server-side with Supabase encryption. Discover how keys are protected from browser exposure and repository commits for safe GPT-Image2 generation.

- Repository: [苍何/awesome-gpt-image-2](https://github.com/freestylefly/awesome-gpt-image-2)
- Tags: how-to-guide
- Published: 2026-09-06

---

**Personal APIMart API keys in awesome-gpt-image-2 are stored server-side in Supabase, encrypted at rest, and injected into requests only on the backend—never exposed to the browser or committed to the repository.**

The awesome-gpt-image-2 project implements a **security-first architecture** for managing personal APIMart API keys used to power GPT-Image2 generation. Rather than hard-coding credentials or shipping them to the client, the codebase isolates sensitive key material entirely within server-side functions and encrypted database storage. This article examines the complete key lifecycle from registration through validation to deletion.

## Server-Side Key Storage Architecture

When a user registers a personal APIMart key, the system immediately moves that credential away from any client-accessible surface.

The [`/api/me.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main//api/me.js) endpoint receives the key from a trusted frontend form and persists it to the Supabase `user_credits` table. The relevant migration at [`supabase/migrations/20260500190000_user_credits.sql`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/supabase/migrations/20260500190000_user_credits.sql) defines the `apimart_key` column, which benefits from **Supabase's automatic encryption at rest**. The raw key therefore never appears in the repository, in browser DevTools, or in server logs.

```js
// api/me.js – Saving a user's personal API key
import { supabase } from "../../src/supabaseClient";

export default async function handler(req, res) {
  const { apiKey } = req.body;   // received from a trusted front-end form
  const { user } = await supabase.auth.getUser();
  await supabase
    .from("user_credits")
    .update({ apimart_key: apiKey })
    .eq("id", user.id);
  res.status(200).end();
}

```

## Environment-Only Configuration for Global Credentials

The backend services that communicate with APIMart's infrastructure source their **global** authentication from environment variables defined in `.env.example`. The `APIMART_API_KEY` variable is injected by Vercel at deployment time and is explicitly excluded from version control via `.gitignore`.

This pattern ensures that even developers with repository access cannot view production credentials without explicit infrastructure permissions.

## Per-User Request Handling with Server-Side Key Injection

The heart of the APIMart API key handling system resides in [`src/apimartClient.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/src/apimartClient.js). This module retrieves the **current user's specific key** from the authenticated Supabase session, then attaches it to every outbound request via the `Authorization: Bearer <key>` header.

Critically, this client executes **only in serverless functions**, meaning the key never transits to the browser or becomes visible in frontend JavaScript bundles.

```js
// src/apimartClient.js – Adding the user's key to each request
import { supabase } from "./supabaseClient";

export async function apimartFetch(path, options = {}) {
  const { data: user } = await supabase.auth.getUser();
  const apiKey = user?.apimart_key;               // <-- per-user key
  const headers = {
    ...options.headers,
    Authorization: `Bearer ${apiKey}`,            // sent only server-side
  };
  const resp = await fetch(`https://api.apimart.com${path}`, {
    ...options,
    headers,
  });
  return resp.json();
}

```

The [`api/generate-image.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/api/generate-image.js) endpoint demonstrates this pattern in practice: it imports `apimartFetch` and delegates all APIMart communication to the client, keeping key management concerns separated from generation logic.

```js
// api/generate-image.js – Using the client to request image generation
import { apimartFetch } from "../../src/apimartClient";

export default async function handler(req, res) {
  const { prompt } = req.body;
  const result = await apimartFetch("/v1/generate", {
    method: "POST",
    body: JSON.stringify({ prompt }),
    headers: { "Content-Type": "application/json" },
  });
  res.status(200).json(result);
}

```

## Key Validation Before Generation

Before queuing any image generation job, the system validates the supplied APIMart API key. The [`api/generation/status.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/api/generation/status.js) endpoint performs a lightweight "ping" request to APIMart to verify key validity.

If validation fails—whether due to an invalid, expired, or missing key—the endpoint returns **401 Unauthorized**. The frontend surfaces this as a user-friendly warning directing the user to supply a valid key in their account settings.

This validation layer prevents wasted compute resources and provides clear feedback loops for credential issues.

## Key Removal and Data Lifecycle

Users retain full control over their stored credentials. Through the same [`/api/me.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main//api/me.js) endpoint, a deletion request clears the `apimart_key` column for that user in Supabase. Subsequent generation attempts immediately fail with authentication errors until a new valid key is provided.

This design supports **privacy-by-default principles**: no key persists longer than user consent allows, and removal is instantaneous rather than batched or delayed.

## Summary

- **Encrypted storage**: Personal APIMart API keys live in Supabase `user_credits` table with automatic encryption at rest, never in repository code.
- **Server-side isolation**: The [`src/apimartClient.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/src/apimartClient.js) module handles all key injection server-side; keys never reach browser environments.
- **Environment-based globals**: Service-level credentials use Vercel-injected environment variables per `.env.example` specifications.
- **Validation gates**: [`api/generation/status.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/api/generation/status.js) verifies key validity with a ping request before allowing generation jobs.
- **User-controlled deletion**: Keys can be permanently removed via [`/api/me.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main//api/me.js), with immediate effect on subsequent operations.

## Frequently Asked Questions

### How does awesome-gpt-image-2 prevent APIMart API keys from leaking to the frontend?

The architecture strictly separates client and server boundaries. The [`src/apimartClient.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/src/apimartClient.js) module runs exclusively in Vercel serverless functions, retrieves keys from Supabase sessions server-side, and injects them into `Authorization` headers before any network request. Frontend code never imports this module or receives key material in API responses.

### What database table stores personal APIMart API keys?

The `user_credits` table defined in [`supabase/migrations/20260500190000_user_credits.sql`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/supabase/migrations/20260500190000_user_credits.sql) contains the `apimart_key` column. Supabase encrypts this data at rest automatically, and row-level security policies restrict access to the authenticated owner of each record.

### Can users remove their stored APIMart key from the system?

Yes. Sending a request to the [`/api/me.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main//api/me.js) endpoint with a null or empty `apiKey` body value clears the stored key for the authenticated user. The update takes effect immediately, and subsequent image generation attempts will fail with authentication errors until a new key is provided.

### What happens if an invalid APIMart API key is submitted for GPT-Image2 generation?

The [`api/generation/status.js`](https://github.com/freestylefly/awesome-gpt-image-2/blob/main/api/generation/status.js) validation layer detects invalid keys through a lightweight APIMart ping request. The endpoint returns HTTP 401 with an error message, which the frontend renders as a warning prompting the user to check and re-enter their API key.