BlogForms

A key that belongs in view source

Public keys let a frontend use your plan directly. Give each key an allowed domain list, including localhost for development.

If a signup form calls an API from the browser, the key is visible to anyone who opens the developer tools. We have a key type for that:

parse_public_xxxxxxxxxxxxxxxxxxxx

A public key has access to the endpoints and allowances on your plan. When you create it on the keys page, you give it a list of allowed domains. example.com covers the domain itself and its subdomains, so app.example.com works too. Add localhost to that list if you want to use the key during local development.

The API checks the request's origin, or its referrer when an origin is absent, against the list. A request without an allowed hostname is rejected. Scripts can supply those headers too, so the restriction does not turn an exposed key into a secret.

The prefix makes the intended use visible. A parse_public_ key in frontend code belongs there. A parse_ secret key belongs on your server.

For a form that checks email addresses or formats phone numbers, this lets the frontend call ParseAPI directly. You can still route requests through your own server when your application needs to control who can make them.