Hacker News new | ask | show | jobs
by brycecammo 5118 days ago
> I'm still a but curious as to what a nefarious user could do with your "publishable API key,"

I suspect very little if they don't also have your 'secret' API key. I guess they could request a single-use token for a card, but I don't think they could then do anything with it.