The client key identifies your SDK end point, and that's public
fresh-football-47124
12/03/2024, 10:55 AM
the API key, that should be kept secret if you created one
fresh-football-47124
12/03/2024, 10:55 AM
you can look at the SDK end point to see what its returning
fresh-football-47124
12/03/2024, 10:55 AM
it will contain the flags, and any rules and targeting conditions
fresh-football-47124
12/03/2024, 10:56 AM
this usually is safe and has no PII - but you can taget to a list of emails, or other PII and that may be exposed. We recommend not doing that or using hashed attributes in those cases