Skip to content
Back to journal
Google AI StudioAI BuilderWeb to App

Deploy a Google AI Studio App Without Leaking Your API Key

CCode2Native EngineeringEngineering team
Published

Want to see your own site as an app? Paste its address: the free preview shows it in a phone frame. No account needed.

Google AI Studio deploys the web app you built to Google Cloud Run from its Build mode. On the Starter Tier, eligible accounts deploy up to two apps without a Google Cloud project or a billing account. In apps built since May 14, 2026, your Gemini API key stays on the server and never reaches the browser, but it pays for every visitor's Gemini calls, so decide who gets the link before you share it.

Two ways to deploy

OptionWhat it needsLimit
Starter TierAn eligible account (not Google Workspace, no active or prior paid Google Cloud billing account); no Google Cloud project or billing accountUp to two services, in a single Cloud Run region
Standard deploymentA Google Cloud project linked to your AI Studio account, with billing enabledSet by your Google Cloud project

Source: Google's Deploying from Google AI Studio, checked October 3, 2026. To move from the Starter Tier to standard deployment, you create a Cloud Billing account and accept Google Cloud's Terms of Service.

Your API key stays on the server

A web app built in AI Studio has two parts: a front end that runs in the visitor's browser (React by default) and a Node.js server. Google's Build mode guide says: “API keys are injected into the server-side runtime and are never included in client-side code.” People who use your app cannot see the key. That holds for apps built since May 14, 2026; Google says an older app moves to the server-side approach the next time you change its Gemini features, so make that change before you deploy one.

That protection comes from the server half. If you later move the app to another host, keep the Gemini calls on a server there too: a key that ships in front-end code can be read by anyone who opens the app.

But it pays for every user

The same guide is just as clear about the cost side: “The deployed app will use your API key for all users' Gemini API calls.” Every visitor spends your quota. If the link spreads, your usage limits are reached for everyone at once, and with billing enabled the usage is yours to pay. Before you post the link publicly:

  • Set a monthly spend cap for the key's project in AI Studio (the Spend page, Monthly spend cap). Google bills with a delay of about ten minutes, so usage can run briefly past the cap (Gemini API billing).
  • Share it with the people you mean to first, and watch your Gemini API usage for a few days.
  • If the app should only work for your own users, build sign-in into the app itself.
  • Keep expensive calls behind a deliberate action, such as a button, rather than on every page load.

From the deployed URL to an app

The deployed address is an ordinary website, which is exactly what a website-to-app build needs. Paste it into the free preview to see it in a phone frame first. Before you build for real, settle the address, such as your ai.studio custom URL, and keep the app published: the App license binds the website's address as well as the package name, and Google releases an unpublished app's custom URL for others to claim. Then create the app with the package name you want to keep and, for Google Play, upload your own keystore before its first build, because the signing key is fixed from that build on. Buy the App license for that app ($69): Release APK and AAB for this website, without the Code2Native watermark. One-time payment. Not on a free Preview of the same site, which is a separate app signed with our shared key. The Android path is in how to get an APK from Google AI Studio; for iPhone, see the App Store review checklist.

See your website as an app

The preview loads your live site in a phone frame. When it looks right, open an account and build it. Build one Preview APK with a Code2Native watermark. No card required.

Open an account and build →

Frequently asked questions

Is deploying from Google AI Studio free?

On the Starter Tier, eligible accounts can deploy up to two services without a Google Cloud project or billing account. Google Workspace accounts and accounts with an active or prior paid Google Cloud billing account are not eligible. Beyond that, standard deployment needs a Google Cloud project linked to your AI Studio account, with billing enabled on it.

Can people see my Gemini API key in a deployed app?

In apps built since May 14, 2026, no: Google says the key is stored as a secret in the app's server-side environment and never included in client-side code. An older app moves to that approach the next time you change its Gemini features, so do that before you deploy it.

Who pays for the Gemini calls my users make?

Your key does. Google's docs say the deployed app uses your API key for all users' Gemini API calls, so every user's calls count toward your usage limits, and with paid models, costs may apply. A monthly spend cap in AI Studio limits that.

Can I turn the deployed app into an Android or iPhone app?

Yes. The deployed URL is a website, and a website can be wrapped as an app: preview it free, then buy an App license for a release APK and AAB, or an unsigned IPA for iPhone.

C

Code2Native Engineering

Engineering team

Written by the Code2Native engineering team — the people who build and operate the cloud build pipeline.