Security & Privacy

Security & Privacy in SnippKit provides controls for managing API secret keys, scoping extension tokens, and inspecting active device authentication sessions.
SnippKit prioritizes data privacy, zero-latency client processing, and strict authorization controls across all web endpoints, CLI commands, and extensions.

Overview

Your code snippets, API keys, and team playbooks represent valuable developer intellectual property.
Through SnippKit’s Developer Settings (/settings/developer) and Device Access diagnostics (/settings/device), you retain strict control over API access keys and authenticated device sessions.
Direct App Shortcut
Manage API secret keys at Settings → Developer (/settings/developer) or inspect device permissions at Settings → Device (/settings/device).

What you can do

With Security & Privacy, you can:
  • API Secret Key Management: Generate, scope, or immediately revoke API secret keys (sk_live_...) for extensions and CLI access.
  • Session & Access Control: Manage active login sessions and verify authenticated devices.
  • Extension Token Scoping: Securely connect VS Code and Chrome extensions using personal access tokens.

Security Features Matrix

FeatureScope & DescriptionLocation
API Key ManagementGenerate or revoke secret access tokens (sk_live_...) used by VS Code, Chrome extension, and SNiX CLI./settings/developer
Session ManagementInspect active login sessions, revoke unauthorized device tokens, and enforce passwordless OAuth authentication./settings/device

API Key Security Best Practices

When using SnippKit API keys (sk_live_...):
  • Never Commit Secret Keys: Keep API secret keys out of public Git repositories.
  • Revoke Exposed Keys: If a key is accidentally committed, open /settings/developer and click Revoke Key immediately.
  • Use Bearer Tokens for JaaS: When accessing private JSON as a Service endpoints, include Authorization: Bearer <sk_live_key> in HTTP request headers.

Copyright © 2026 SnippKitUp to date