Create a short security checklist for a browser client that submits API jobs. Keep the answer practical for a gemini-3.1-flash-lite-preview integration.
Keep secrets server-side, authenticate every request, validate payloads before forwarding, use short-lived signed URLs for assets, and log security-relevant failures without recording secrets. This example is tailored to the gemini-3.1-flash-lite-preview model page.