Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
World desk6 min

API Key Security: Store, Scope, Rotate, and Revoke Credentials Safely

Keep API keys out of repositories and client apps, store them behind controlled access, limit permissions, and have a tested process to rotate or revoke them.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep API keys out of code, repositories, browser and mobile apps, and build artifacts. Store them where access is controlled, limit what each key can do, and revoke a key immediately if it may have been exposed. An API key can identify or authorize a request, but it is not a complete security design for sensitive resources.

What an API key protects—and what it does not

An API key is a credential: whoever obtains it may be able to make requests under the permissions and usage limits associated with it. That makes secrecy essential, but secrecy alone is not enough. A key may have broad permissions, remain valid indefinitely, or be copied into places where you cannot reliably control access.

As an Amazon Associate I earn from qualifying purchases.

OWASP notes that API keys can help limit API farming and excessive compute or bandwidth use, and can support usage plans. It also warns that third-party-issued keys are relatively easy to compromise and should not be the sole protection for sensitive, critical, or high-value resources. Add authorization checks and, where appropriate, network restrictions, rate limits, and monitoring. OWASP REST Security Cheat Sheet

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where should you store an API key?

Choose storage based on who or what needs access, how the key is deployed, and how quickly you need to revoke or replace it. The key should be available to the server-side process that needs it, not exposed to every user who can inspect a client application.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Storage approach Best suited to Key security questions
Local environment variable or local development configuration Individual development and local testing Is the value kept out of source control, logs, shell history, and shared machine accounts? Environment variables separate configuration from source code, but are not a vault or a guarantee against leakage.
CI/CD platform secret storage Build and deployment workflows that need credentials Which workflows and maintainers can access it? Is it limited to the right repository, environment, and job? Could it appear in logs or artifacts?
Cloud-provider secret store or vault Applications running in a cloud environment, especially when provider-native access controls fit Can access be granted to the specific workload? Are access events, rotation, recovery, and availability covered?
Dedicated secrets-management system Teams needing centralized policy, cross-platform access, audit, or lifecycle controls Can the team operate it reliably, integrate it with applications, restore it, and manage its added administrative complexity?

There is no single best storage vendor or mechanism for every team. OWASP recommends a dedicated secrets-management solution or key vault rather than committing secrets to a repository or embedding them in build artifacts. Its guidance also stresses lifecycle controls, access auditing, availability, and backup and recovery. OWASP Secrets Management Cheat Sheet

For local development

Keep development credentials separate from source files and use a distinct key from production. An environment variable can be a practical way to supply a local configuration value without hard-coding it in application code. Still check where your shell, editor, local tools, and logs may expose it, and ensure the configuration file containing the value is excluded from version control.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

For CI/CD and production

Use the CI/CD platform’s protected secret mechanism for build or deployment credentials, and grant access only to workflows that need it. For a running production application, use a controlled server-side mechanism or a secret store. Separate development and production credentials so exposure in one environment does not automatically expose the other. For supported workloads, OpenAI recommends considering workload identity federation instead of a long-lived API key. OpenAI API key safety guidance

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For credentials shared among people

Prefer individual identities and keys when the provider supports them. If a team must share a credential, use a controlled shared system with access limited to the people who need it; do not put the value in chat, a shared document, or a repository. A team credential-sharing tool does not automatically provide the workload identity, audit, and lifecycle controls a production application may require.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How to prevent an API key from leaking

  • Do not commit it. Never place a plaintext key in public or private source repositories. A private repository still exposes content to people and systems with repository access, and the key may persist in commit history after removal.
  • Do not ship it to clients. Never put a secret API key in browser code, a mobile app, or a client-side configuration file. Users can inspect application code and network activity. Route requests that require a secret through a backend you control. OpenAI API key safety guidance
  • Keep it out of build outputs. Check bundles, packages, container images, logs, and deployment artifacts. Removing a key from source does not help if a build has already copied it elsewhere.
  • Use least privilege and separation. Give each person or workload a distinct credential where available, limit permissions to what it needs, and separate keys by service, project, and environment when those controls exist.
  • Choose authentication for the task. GitHub, for example, recommends personal access tokens for personal use, GitHub Apps for actions on behalf of an organization or another user, and the built-in GITHUB_TOKEN for GitHub Actions workflows. Avoid broad credentials when a narrower option fits. GitHub credential guidance
  • Use detection as a backstop. Secret scanning can detect supported credentials pushed to a repository and may block some future pushes. It cannot guarantee detection of every secret or undo exposure, so it does not replace secure storage and prompt revocation.

How to choose the right controls

For a personal project, use a separate development key, keep it out of source control and client code, and know how to revoke it. For a production service, evaluate the entire path from key creation to runtime use and emergency replacement.

  • Exposure boundary: Which people, workloads, administrators, build jobs, and support staff can read or use the credential?
  • Scope and isolation: Can you limit permissions by key, project, service, application, or environment? Can development and production be separated?
  • Lifecycle: Can a key expire, rotate, or be revoked? Can you replace it without a prolonged outage?
  • Audit and monitoring: Can you tell what accessed or changed the secret, and spot abnormal API usage?
  • Availability and recovery: What happens if the secret store is unavailable? Are encrypted backups, restoration tests, and a break-glass procedure in place?
  • Integration and operating burden: Does the mechanism integrate with your application and deployment pipeline, and can your team operate it reliably? A dedicated system can add meaningful complexity.

Use provider-native controls when they meet your threat model and operational needs. Consider a dedicated secrets manager when centralized access policy, audit, rotation, or use across platforms justifies the extra system. OWASP recommends risk-based rotation rather than a universal interval: the right schedule depends on the credential, its purpose, exposure, and operational context. OWASP Key Management Cheat Sheet

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Rotate and monitor keys before an incident

Where the provider supports expiration, set it in line with the credential’s purpose and replacement process. Establish a rotation procedure that identifies dependent applications, updates the secret store, verifies the new credential works, and removes the old one. A rotation that cannot be completed safely is not an effective control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Monitor provider usage and spending for unexpected activity. OpenAI recommends usage monitoring and spend controls, but notes that spend limits may not stop traffic instantaneously and can slightly overshoot; do not treat a configured limit as a guaranteed hard ceiling. OpenAI API key safety guidance

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What to do if an API key leaks

Treat a key as compromised if it appears in a repository, client bundle, build artifact, log, or other place outside its intended boundary—even if the exposure was brief or the repository was private. Removing the visible copy is not enough: other copies may persist in history, logs, caches, or deployments.

  1. Revoke or rotate the exposed credential at the issuing provider. Do not wait for proof of misuse.
  2. Create a replacement with the narrowest practical permissions. Use a separate credential for the affected workload if possible.
  3. Update dependent systems. Replace the old value in applications, deployment settings, CI/CD secrets, and any other configuration that used it; verify the replacement works.
  4. Delete or disable the compromised credential. GitHub’s guidance similarly recommends generating a replacement, updating its use, and deleting the compromised credential. GitHub credential guidance
  5. Investigate where it went. Check repository history, CI logs, artifacts, client bundles, and deployment outputs for additional copies.
  6. Review usage and billing. Look for unexpected requests or charges and follow the provider’s process for reporting unauthorized activity.

Secret scanning can help find exposure, but it is a detection measure—not a substitute for revocation and replacement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.