When you add Ably to a browser or mobile app, keep the API key on your server and expose a token endpoint. The client uses authUrl or authCallback to fetch a token per user with a clientId and scoped capabilities. Shipping the raw API key in client code gives every user full, unexpiring access to your app.

Context: Ably docs (chat setup guide): client-side applications must use JWT authentication. API keys should never be exposed in client-side code because they dont expire and cannot be scoped to specific users. The server issues short-lived tokens via createTokenRequest; the client fetches them with authCallback or authUrl.