Free guide3 min read

Security Checklist

Never expose your keys. This is like handing a stranger your wallet and password combined. Run through this before you deploy anything.

Ryan FrizellePublished Mar 27, 2026

What you'll walk away with

  • The four checks I run before every single deploy
  • The audit prompt that finds exposed keys and missing auth
  • Where your secrets should live so they never reach GitHub

I learned this the hard way. API keys are how platforms talk to each other. If someone gets ahold of your keys, they can edit your apps, and can spend your API tokens if your tokens cost money (you will know API keys cost money if you had to put a card down for a platform). This checklist is what I run through before every single deploy.

01

Check your auth

Authentication checks:

  1. 1Every API route calls requireAuth(). No exceptions.
  2. 2Session tokens stored in HTTP-only cookies.
  3. 3Password minimum 8 characters enforced.
  4. 4Magic link or OAuth preferred over password-based auth.
02

Check your database

Database checks:

  1. 1Row Level Security (RLS) enabled on every table. This is the single most important thing in Supabase.
  2. 2All queries scoped to user_id so users can only see their own data.
  3. 3No raw SQL. Use parameterized queries (Drizzle ORM handles this for you).
03

Check your keys

Environment checks:

  1. 1.env.local is in your .gitignore. If it is not, your secrets will be pushed to GitHub.
  2. 2No secrets in client-side code. Anything with NEXT_PUBLIC_ prefix is visible to everyone.
  3. 3Service role key only used server-side. Never in a component or page file.
04

Check your API routes

API route checks:

  1. 1Input validation on all endpoints. Never trust what comes in from the client.
  2. 2Generic error messages only. No stack traces, no internal details.
  3. 3Rate limiting on auth endpoints to prevent brute force.
  4. 4Webhook signature verification on payment endpoints.
05

The audit prompt

Copy-paste promptSecurity audit prompt for Claude Code
Audit this entire project for security issues. Check every API route for auth protection, every database query for RLS compliance, every environment variable for exposure risk, and every form for input validation. List every issue you find with the file path and line number.
tap to copy

The full course includes my complete security.ts utility library that handles auth, input validation, and rate limiting out of the box.

The Claude Code Course

Liked this? There's 50x more in the course.

  • Getting Started setup guide + prompts
  • Quick Wins library (growing monthly)
  • Step-by-step website and dashboard builds
  • All future sections + updates forever
Get the Full Course

$47 once. Keep forever. Full refund within 14 days.

Follow along

Follow me on socials.

New builds and walkthroughs every week, all free. The guides on this site start as short videos over there.