DEV Community

Cogweald
Cogweald

Posted on

Keep AI services out of Client Components

This is not just a Next.js style preference. It is a security boundary.

Cogweald keeps OpenAI, Supabase service-role access, billing, and the simulation engine in server-only code. Client Components can call controlled server actions or route handlers, but they never import those services directly.

The reasons are practical:

  • API keys must not enter the browser bundle.
  • A service-role client must not be exposed to users.
  • Chapter generation needs authorization and state validation.
  • Billing actions must run in a trusted server context.

AI apps often put sensitive calls in the browser just to make the first button work, then try to repair the boundary after deployment. A better approach is to establish it in the import graph from the beginning: which modules are server-only, and which data is safe to send to the client?

A feature can be finished later. Secrets should never be shipped first.

Top comments (0)