Client and server — two computers, two jobs
This is the most important idea in the course, because the whole track's safety rule depends on it and course 1 lesson 3 assumes you already have it.
Two places, and only one is yours
The client is the browser on someone's machine. It runs the code you sent them.
The server is a machine you control. It runs code nobody else can see.
A web page is a conversation between them: the browser asks, the server answers.
What "the browser can read it" actually means
Everything the browser runs, the person using the browser can read. Not with special tools — right-click, View Source, or open the developer tools that ship with every browser.
So this sentence has a hard, checkable meaning: anything you put in client code is public. Not "discouraged". Public.
That is the whole reason for the rule you are about to meet in course 1. An API key in client code is not a risk of exposure; it is exposure, to everyone who ever loads the page.
The shape that fixes it
browser ──► your server ──► the market data API
◄── ◄──
The browser asks your server. Your server holds the key, asks the real API, and passes back only what the page needs. The key never travels to a machine you do not control.
Course 1 calls this a proxy and builds it in one lesson. It is about fifteen lines, and everything else in this academy sits behind it.
How to tell which side code runs on
You will be reading generated code and needing to answer this constantly. Two reliable signals in the framework this track uses: a file marked "use client" runs in the browser, and an environment variable whose name starts with NEXT_PUBLIC_ is one the browser can read — the prefix is a warning, not a feature.
Course 1 shows both together in a single component and asks you to spot why it is the worst defect in the course. You will be able to.
Try it now
Open any website, then open your browser's developer tools and look at the Sources or Network tab. That is what every visitor can see of every site, including the one you will deploy at the end of this course. Sitting with that for two minutes does more than any warning.