SUPPORT.TWILIO.COM END OF LIFE NOTICE: This site, support.twilio.com, is scheduled to go End of Life on February 27, 2024. All Twilio Support content has been migrated to help.twilio.com, where you can continue to find helpful Support articles, API docs, and Twilio blog content, and escalate your issues to our Support team. We encourage you to update your bookmarks and begin using the new site today for all your Twilio Support needs.

What Is the Security Impact of Publicly Exposing Source Write Keys?

Question

What is the impact of exposing the source's write keys when using Segment Analytics.js or other client-side tracking libraries?

 

Product

Segment 

 

Environment

Segment Console

 

Answer

Exposing the source's write key is required for client-side tracking with Segment Analytics.js and similar libraries. The write key allows data to be sent to the associated Source but does not provide access to read data or modify configurations. This approach is standard among analytics tools. If unusual activity is detected, a new write key should be generated. To avoid exposing the write key, use Segment’s HTTP Tracking API or a server-side library.

Have more questions? Submit a request
Powered by Zendesk