You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在前端使用LinkedIn JavaScript SDK授权且不暴露API密钥?

Why LinkedIn's Frontend Script Exposes Your API Key (And Why It's Actually Safe)

Great question—this is a super common point of confusion when working with OAuth-based auth flows, so you’re definitely not alone in scratching your head over this. Let’s break down what’s going on here:

First, let’s clarify a critical distinction: your API key is not a sensitive secret (unlike your API secret, which should never, ever be exposed in frontend code). Here’s why:

  • The API key is meant to publicly identify your application to LinkedIn’s servers. Anyone who interacts with your app can already see it via network requests (even if you didn’t put it in the script tag—browser dev tools would show it in authorization headers or query params).
  • The real security guardrail is your API secret, which lives exclusively on your backend. This secret is used to verify that requests to exchange authorization codes for access tokens are coming from your trusted server, not a malicious actor.

Now, let’s look at LinkedIn’s JS SDK script:

<script type="text/javascript" src="//platform.linkedin.com/in.js">
  api_key: [API_KEY]
  onLoad: [ONLOAD]
  authorize: [AUTHORIZE]
  lang: [LANG_LOCALE]
</script>

This script is just initializing the SDK and triggering the authorization flow. When the user grants access, the frontend will either get an authorization code (if using the authorization code flow) or a short-lived access token (if using implicit flow).

For production apps, you should always use the authorization code flow:

  1. The frontend gets an authorization code after user approval.
  2. You send this code to your backend server.
  3. Your backend uses the code, plus your API key and secret, to exchange for a long-lived access token from LinkedIn.
  4. All subsequent requests to fetch sensitive user data are made from your backend using this token.

This way, even if someone gets their hands on your API key, they can’t do anything harmful without your secret.

To add an extra layer of security, head to your LinkedIn Developer Dashboard and set valid OAuth redirect URIs and allowed domains for your app. This restricts which domains can use your API key to initiate auth flows, preventing unauthorized misuse.

So to sum up: exposing your API key in the frontend script is intentional and safe—just make sure your API secret stays locked away on your server.

内容的提问来源于stack exchange,提问作者Edmond Petres

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 09:21:54