{
  "id": 10499093,
  "title": "Your Next.js API route is public—even if your UI isn’t.",
  "url": "https://urgent.news/2026/09/28/your-next-js-api-route-is-public-even-if-your-ui-isnt",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-28T18:00:32.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/webdecoy/your-nextjs-api-route-is-public-even-if-your-ui-isnt-31l4"
  },
  "original_language": "en",
  "account": "Public API routes in Next.js, even if not visible to users, remain accessible to anyone who knows their URL. This can be problematic for forms, as an attacker could submit data directly to the route. To prevent unauthorized access, a server needs to verify the request. The example demonstrates using Next.js App Router route handlers with a free open-source project called FCaptcha. FCaptcha handles a client-side form submission, collects a token, and sends it to the server for validation. The server-side code then completes the verification process using the received token, ensuring that only legitimate submissions are processed.",
  "summary": "Hiding a form behind a client-side condition doesn't make its API route private. Unless the route enforces its own checks, another client can call it directly. For a public contact form, you may not want to require an account. You still want the server to validate the request before it triggers an email or database write. This example uses a Next.js App Router route handler and self-hosted…",
  "key_points": [
    "Public API routes in Next.js are accessible even if UI is not visible.",
    "Unauthorized data submission possible via direct URL access.",
    "FCaptcha provides server-side form verification solution."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}