How Personal APIMart API Keys Are Handled for GPT-Image2 Generation in awesome-gpt-image-2
Personal APIMart API keys in awesome-gpt-image-2 are stored server-side in Supabase, encrypted at rest, and injected into requests only on the backend—never exposed to the browser or committed to the repository.
The awesome-gpt-image-2 project implements a security-first architecture for managing personal APIMart API keys used to power GPT-Image2 generation. Rather than hard-coding credentials or shipping them to the client, the codebase isolates sensitive key material entirely within server-side functions and encrypted database storage. This article examines the complete key lifecycle from registration through validation to deletion.
Server-Side Key Storage Architecture
When a user registers a personal APIMart key, the system immediately moves that credential away from any client-accessible surface.
The /api/me.js endpoint receives the key from a trusted frontend form and persists it to the Supabase user_credits table. The relevant migration at supabase/migrations/20260500190000_user_credits.sql defines the apimart_key column, which benefits from Supabase's automatic encryption at rest. The raw key therefore never appears in the repository, in browser DevTools, or in server logs.
// api/me.js – Saving a user's personal API key
import { supabase } from "../../src/supabaseClient";
export default async function handler(req, res) {
const { apiKey } = req.body; // received from a trusted front-end form
const { user } = await supabase.auth.getUser();
await supabase
.from("user_credits")
.update({ apimart_key: apiKey })
.eq("id", user.id);
res.status(200).end();
}
Environment-Only Configuration for Global Credentials
The backend services that communicate with APIMart's infrastructure source their global authentication from environment variables defined in .env.example. The APIMART_API_KEY variable is injected by Vercel at deployment time and is explicitly excluded from version control via .gitignore.
This pattern ensures that even developers with repository access cannot view production credentials without explicit infrastructure permissions.
Per-User Request Handling with Server-Side Key Injection
The heart of the APIMart API key handling system resides in src/apimartClient.js. This module retrieves the current user's specific key from the authenticated Supabase session, then attaches it to every outbound request via the Authorization: Bearer <key> header.
Critically, this client executes only in serverless functions, meaning the key never transits to the browser or becomes visible in frontend JavaScript bundles.
// src/apimartClient.js – Adding the user's key to each request
import { supabase } from "./supabaseClient";
export async function apimartFetch(path, options = {}) {
const { data: user } = await supabase.auth.getUser();
const apiKey = user?.apimart_key; // <-- per-user key
const headers = {
...options.headers,
Authorization: `Bearer ${apiKey}`, // sent only server-side
};
const resp = await fetch(`https://api.apimart.com${path}`, {
...options,
headers,
});
return resp.json();
}
The api/generate-image.js endpoint demonstrates this pattern in practice: it imports apimartFetch and delegates all APIMart communication to the client, keeping key management concerns separated from generation logic.
// api/generate-image.js – Using the client to request image generation
import { apimartFetch } from "../../src/apimartClient";
export default async function handler(req, res) {
const { prompt } = req.body;
const result = await apimartFetch("/v1/generate", {
method: "POST",
body: JSON.stringify({ prompt }),
headers: { "Content-Type": "application/json" },
});
res.status(200).json(result);
}
Key Validation Before Generation
Before queuing any image generation job, the system validates the supplied APIMart API key. The api/generation/status.js endpoint performs a lightweight "ping" request to APIMart to verify key validity.
If validation fails—whether due to an invalid, expired, or missing key—the endpoint returns 401 Unauthorized. The frontend surfaces this as a user-friendly warning directing the user to supply a valid key in their account settings.
This validation layer prevents wasted compute resources and provides clear feedback loops for credential issues.
Key Removal and Data Lifecycle
Users retain full control over their stored credentials. Through the same /api/me.js endpoint, a deletion request clears the apimart_key column for that user in Supabase. Subsequent generation attempts immediately fail with authentication errors until a new valid key is provided.
This design supports privacy-by-default principles: no key persists longer than user consent allows, and removal is instantaneous rather than batched or delayed.
Summary
- Encrypted storage: Personal APIMart API keys live in Supabase
user_creditstable with automatic encryption at rest, never in repository code. - Server-side isolation: The
src/apimartClient.jsmodule handles all key injection server-side; keys never reach browser environments. - Environment-based globals: Service-level credentials use Vercel-injected environment variables per
.env.examplespecifications. - Validation gates:
api/generation/status.jsverifies key validity with a ping request before allowing generation jobs. - User-controlled deletion: Keys can be permanently removed via
/api/me.js, with immediate effect on subsequent operations.
Frequently Asked Questions
How does awesome-gpt-image-2 prevent APIMart API keys from leaking to the frontend?
The architecture strictly separates client and server boundaries. The src/apimartClient.js module runs exclusively in Vercel serverless functions, retrieves keys from Supabase sessions server-side, and injects them into Authorization headers before any network request. Frontend code never imports this module or receives key material in API responses.
What database table stores personal APIMart API keys?
The user_credits table defined in supabase/migrations/20260500190000_user_credits.sql contains the apimart_key column. Supabase encrypts this data at rest automatically, and row-level security policies restrict access to the authenticated owner of each record.
Can users remove their stored APIMart key from the system?
Yes. Sending a request to the /api/me.js endpoint with a null or empty apiKey body value clears the stored key for the authenticated user. The update takes effect immediately, and subsequent image generation attempts will fail with authentication errors until a new key is provided.
What happens if an invalid APIMart API key is submitted for GPT-Image2 generation?
The api/generation/status.js validation layer detects invalid keys through a lightweight APIMart ping request. The endpoint returns HTTP 401 with an error message, which the frontend renders as a warning prompting the user to check and re-enter their API key.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →