API Token not needed for Data API access? Dangerous

Hi fam, I’ve enabled DATA API on my site and created an API token as well to restrict the data access to request with the specific private key only.

However, I tried and found that I could access the data without the private key. Could someone help me to look at this? This would expose my data publicly.

Do help, fam,

Care to share a screenshot of your data api tab in the settings of your project?

Might be worth checking out @petter latest article 10 Easy Bubble Security Tips


Might be good to check the privacy settings, too.


Alright, thanks fam!

I’ll send over the screenshot and read the article tomorrow. It’s a little bit later here in my Timezone.

Thank you so much for helping out!

