> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.repliers.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Client-Side API Keys Developer Guide

## Overview

Repliers now supports client-side API keys, enabling faster search performance and simplified implementation by allowing direct API calls from your frontend applications. This approach eliminates the need for server-side proxying while maintaining security through our [API firewall](https://repliers.com/strengthening-data-security-introducing-our-new-ip-forwarding-feature/) that automatically scans IP addresses and traffic patterns. You can read more about this feature in our [blog](https://repliers.com/introducing-client-side-api-keys-faster-searches-with-repliers/).

## Key Benefits

**Performance Improvements**: Direct client-to-API communication reduces latency by eliminating the server middleware layer, resulting in significantly faster search responses.
**Simplified Architecture**: Remove the complexity of server-side API proxying and authentication handling from your backend infrastructure. This is particularly beneficial for modern frontend applications, rapid prototyping, and "vibe-coded" applications where developers prioritize quick iteration and direct implementation over complex backend architectures. Server-side proxies aren't commonly used in these development approaches.
**Enhanced User Experience**: Faster search results improve user engagement and application responsiveness.

## Security Model

Client-side API keys are protected by our advanced security infrastructure:

* **API Firewall Protection**: Automatic IP address scanning and traffic pattern analysis detect and block suspicious activity
* **Domain Configuration**: Optional additional layer where you can specify allowed domains for your API key
* **Safe Client-Side Usage**: Keys can be embedded in client-side code since the primary security relies on our firewall systems

## Getting Started

### Step 1: Generate a Client-Side API Key

1. Navigate to the [Repliers Developer Portal](https://login.repliers.com)
2. Go to **API Keys** section
3. Click **Create New Key**
4. Select **Client-Side** as the key type
5. Configure your allowed domains using Authorized Domains setting
6. Save and copy your new API key

### Step 2: Configure Base URL and Implementation

#### Base URL configuration

When using client-side API keys, you must use the client-side API base URL `https://csr-api.repliers.io` instead of the standard `https://api.repliers.com` endpoint.
Make direct client-side requests to the Repliers API, including your client-side API key in the request parameters. You can use this approach alongside existing server-side implementations when needed for other functionality.

#### Allowed endpoints

Currently the following API endpoints are accessible for Client-Side API Keys:

* `GET /listings`
* `POST /listings`
* `GET /locations`
* `GET /locations/autocomplete`

**Important**: Not all API endpoints are available for client-side use. Endpoints that return sensitive information (such as clients and agents endpoints) should continue to use server-side proxies with regular API keys to protect sensitive data.

## Security Considerations

* **Environment Management**: Use different API keys for development, staging, and production
* **Key Rotation**: Periodically rotate your API keys as part of security best practices

# What questions does this article answer?

* What are client-side API keys in Repliers and when should I use them?  
* How do client-side keys differ from traditional server-side API keys?  
* What performance and architectural benefits do client-side keys provide?  
* How does Repliers’ API firewall protect client-side keys from abuse?  
* How do I generate a client-side API key in the Developer Portal?  
* Which base URL should I use for client-side API calls?  
* Which endpoints are allowed with client-side API keys and which are not?  
* What security practices (environments, rotation) should I follow with client-side keys?  