What you’ll be able to do
- Separate browser UI from privileged model access.
- Use the Responses API with a deployment name.
- Define privacy, validation, and abuse controls before publishing.
Get the idea
A narrow AI task is easier to verify
Summarizing a fictional support request is more reviewable than an unrestricted autonomous agent. Define a concise output format and prohibit invented facts. Even with clear instructions, inspect the model output.
Credentials belong on the server
A browser bundle is visible to visitors. Keep API keys in server-side environment settings, or use managed identity where supported. Your backend must authenticate and authorize callers rather than trusting a hidden button.
Bound input and usage
Limit input length, output length, and request frequency. Get permission before sending real organizational data to a model. Plan for timeouts, invalid requests, model errors, and output that does not match your expected format.
Try it yourself
- Download the backend example. Read it before running it: it validates input length, calls a configured deployment, and writes the generated summary to your local terminal.
- Configure AZURE_OPENAI_BASE_URL, AZURE_OPENAI_DEPLOYMENT, and AZURE_OPENAI_API_KEY in your local server environment. Do not paste secrets into the browser, repository, or a prompt.
- Install the openai SDK in your own sample project, save the example as summarize.mjs, and run it with a short fictional request. Model use may incur charges.
- Test empty input and oversized input. Confirm validation rejects them before a model call. Test a fictional request asking the model to ignore the summary instruction and inspect the result critically.
- Before exposing this as a web endpoint, add verified user authorization, usage limits, monitoring, safe error handling, and a privacy review. Use an Azure Functions HTTP trigger or other suitable backend; the provided local script alone does not supply these controls.
Example · commands or prompt
# In your own backend sample project:
npm install openai
# Set the three Azure environment values securely, then:
node summarize.mjs "Fictional request: laptop cannot connect to guest Wi-Fi."Download the exampleFinish the lab
Remove or securely unset sample credentials after testing. Delete unused model deployments and sample resources as appropriate. Do not record secrets or real ticket content in logs.
Quick knowledge check
Can a minified JavaScript bundle safely hide an Azure OpenAI API key?
Reveal the explanation
No. Visitors can inspect browser-delivered code and requests. Place privileged model access behind an authorized server endpoint.
Take this with you
Build fast at the interface; be deliberate at the trust boundary.
Go deeper
AI-assisted lesson · Reference links checked October 3, 2026. Exercises are teaching examples; they have not been executed against your Azure subscription.