# Exposed AWS Credentials on Deployed Frontend

**URL:** <https://discourse.sst.dev/t/exposed-aws-credentials-on-deployed-frontend/300>\
**Category:** General\
**Created:** [June 29, 2018, 5:58pm UTC](https://discourse.sst.dev/t/exposed-aws-credentials-on-deployed-frontend/300 "2018-06-29T17:58:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![iterativescopes](https://avatars.discourse-cdn.com/v4/letter/i/5fc32e/32.png) [@iterativescopes](https://discourse.sst.dev/u/iterativescopes)\
**Post date:** [June 29, 2018, 5:58pm UTC](https://discourse.sst.dev/t/exposed-aws-credentials-on-deployed-frontend/300/1 "2018-06-29T17:58:29Z")

</div>

Hi,

On the final version of the app ([https://demo.serverless-stack.com/](https://demo.serverless-stack.com/)), using the Chrome dev tools, I can dig through the app directory. In Top \> [demo.serverless-stack.com](http://demo.serverless-stack.com) \> static \> js \> main.852cb2a5.js, _all_ of the AWS credentials are visible in plaintext (AWS Region, API URL, user pool ID, App client ID, identity pool ID, etc). Is this not a fairly fatal flaw in this tutorial?

My guess is that the solution is to use EC2 rather than S3 to host the frontend because S3 is made for static hosting (no important environment variables).

Any thoughts?

Best,  
Avi

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [June 29, 2018, 8:53pm UTC](https://discourse.sst.dev/t/exposed-aws-credentials-on-deployed-frontend/300/2 "2018-06-29T20:53:02Z")

</div>

No those are just id’s for the AWS resources we are using. The actual credentials to access them are generated when a user authenticates with our User Pool.
