Client-Side Usage
Use origin-restricted API keys safely in browser JavaScript.
You can call the TrustTrade API directly from browser JavaScript using origin-restricted keys. These keys are safe to embed in client-side code because they only work from specified domains.
Create an origin-restricted key
First, create a key with allowed_origins set:
How origin restriction works
When a key has allowed_origins:
- The API checks the
Originheader against the allowed list - Requests without an
Originheader are rejected (403) - Per-IP rate limiting is enforced (60 requests/min per client IP)
- The per-key rate limit still applies (10 requests/min total)
Browser example
React example
Security considerations
- Origin-restricted keys are safe to include in client bundles — they cannot be used from other domains
- The per-IP rate limit prevents individual users from exhausting your key's quota
- For server-side use, create a separate key without
allowed_origins - Never embed unrestricted keys in client-side code