惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
人人都是产品经理
人人都是产品经理
WordPress大学
WordPress大学
博客园 - Franky
小众软件
小众软件
酷 壳 – CoolShell
酷 壳 – CoolShell
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
IT之家
IT之家
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
Visual Studio Blog
S
SegmentFault 最新的问题
美团技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
有赞技术团队
有赞技术团队
B
Blog RSS Feed
Last Week in AI
Last Week in AI
Jina AI
Jina AI
博客园 - 司徒正美
The Cloudflare Blog
博客园_首页
博客园 - 聂微东
宝玉的分享
宝玉的分享
大猫的无限游戏
大猫的无限游戏

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
Storing a Gemini API Key Securely in a Tauri App — Don't ...
hiyoyo · 2026-05-02 · via DEV Community

All tests run on an 8-year-old MacBook Air.

Every tutorial for Gemini integration shows this:

const API_KEY = "AIzaSy...";

Enter fullscreen mode Exit fullscreen mode

Hardcoded in the frontend. Shipped in the binary. Readable by anyone who opens the app bundle.

For a desktop app, you can do better. Here's how HiyokoLogcat stores the Gemini API key.


The problem with hardcoding

A Tauri app ships as a DMG. The frontend JS is bundled inside the app package. Anyone can unzip the DMG, dig into the resources folder, and read your API key.

Even if you obfuscate it — someone will find it. Security through obscurity isn't security.

The right approach: let the user provide their own API key, store it in the OS keychain or an encrypted local store.


Option 1: tauri-plugin-store (simple)

For most use cases, tauri-plugin-store is enough. It stores data in an encrypted JSON file on the user's machine:

[dependencies]
tauri-plugin-store = "2"

Enter fullscreen mode Exit fullscreen mode

use tauri_plugin_store::StoreExt;

#[tauri::command]
pub fn save_api_key(app: tauri::AppHandle, key: String) -> Result<(), String> {
    let store = app.store("config.json").map_err(|e| e.to_string())?;
    store.set("gemini_api_key", key);
    store.save().map_err(|e| e.to_string())?;
    Ok(())
}

#[tauri::command]
pub fn load_api_key(app: tauri::AppHandle) -> Result, String> {
    let store = app.store("config.json").map_err(|e| e.to_string())?;
    let key = store.get("gemini_api_key")
        .and_then(|v| v.as_str().map(String::from));
    Ok(key)
}

Enter fullscreen mode Exit fullscreen mode

The key lives in ~/Library/Application Support/[your-app]/config.json, encrypted at rest.


Option 2: macOS Keychain (more secure)

For higher security requirements, store in the macOS Keychain via the security CLI:

use std::process::Command;

pub fn save_to_keychain(service: &str, key: &str) -> Result<(), String> {
    Command::new("security")
        .args(["add-generic-password",
            "-s", service,
            "-a", "gemini_api_key",
            "-w", key,
            "-U"])  // -U updates if exists
        .output()
        .map_err(|e| e.to_string())?;
    Ok(())
}

pub fn load_from_keychain(service: &str) -> Result {
    let output = Command::new("security")
        .args(["find-generic-password",
            "-s", service,
            "-a", "gemini_api_key",
            "-w"])  // -w prints password only
        .output()
        .map_err(|e| e.to_string())?;

    Ok(String::from_utf8_lossy(&output.stdout).trim().to_string())
}

Enter fullscreen mode Exit fullscreen mode

Keychain storage survives app reinstalls and is protected by the user's login password.


What I shipped

HiyokoLogcat uses tauri-plugin-store. The settings screen has a password-type input for the API key — the user pastes their key from Google AI Studio, hits save, done.

The key never appears in the UI after initial entry. The Rust backend reads it directly when making API calls — it never surfaces to the frontend JavaScript.


The user experience

"Get a free API key from Google AI Studio, paste it here."

That's it. Users understand this. It takes 2 minutes. And now they own their API key — your app doesn't.


HiyokoLogcat is free and open source → github.com/hiyoyok/HiyokoLogcat
X → @hiyoyok