Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
An API key is a provider-issued credential that lets software identify itself to an API and receive the access, quota, or billing treatment associated with that key. Depending on the provider, it may identify an application, project, account, subscription, or service identity. It may also help enforce permissions and rate limits, but an API key is not automatically a user login, a password, or proof of an end user’s identity.
The exact behavior is provider-specific. For example, Google Cloud says ordinary API keys associate requests with a project for billing and quota but do not authenticate a principal, while Stripe separates publishable, secret, and restricted keys. AWS documents both long-term and short-term service-specific keys. See Google Cloud, Stripe, and AWS for those providers’ definitions.
What does API mean?
An API (application programming interface) is a defined way for one piece of software to request data or actions from another service. A weather app can request current conditions, a checkout system can create a payment, a mapping app can request directions, and an AI application can submit text for processing.
Recommended Free Tools
The API key is one credential used in that request. It is not the API itself.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How an API key works
A simplified request flow looks like this:
Application → API request + key → API provider → validation → response
- The application constructs an HTTP request.
- It sends the key in the header, authorization field, query parameter, or client-library configuration required by the provider.
- The API gateway or service checks whether the key is valid and active.
- It evaluates restrictions such as permitted APIs, endpoints, IP addresses, websites, scopes, quotas, billing status, and request-signature requirements.
- The provider accepts or rejects the request and may record usage against a project, account, subscription, or billing profile.
HTTPS, user authorization, fraud detection, timestamps, nonces, and service-account identity may also be involved. This flow is conceptual; each provider implements its own checks.
What an API key looks like
Keys are usually opaque strings of letters, numbers, and symbols. Some providers use prefixes that indicate the environment or key type, but no prefix convention is universal. Stripe documents examples such as pk_test_... for a publishable test key, sk_test_... for a secret test key, pk_live_... for a publishable live key, and rk_test_... for a restricted test key (Stripe key types).
Use unmistakably fake values in examples:
API_KEY=replace_with_your_key
Google Cloud distinguishes the key string used in requests from an administrative key ID. The ID identifies the key in management systems; it cannot be substituted for the key string in an API call (Google Cloud API keys).
How to send an API key
The API’s own documentation is authoritative. Common patterns include:
Custom HTTP header
curl "https://api.example.com/v1/items"
-H "X-API-Key: replace_with_your_key"
Authorization header
curl "https://api.example.com/v1/items"
-H "Authorization: Bearer replace_with_your_key"
An API may use the Authorization: Bearer format for a key, but the word “Bearer” does not turn that key into an OAuth token.
Query parameter
https://api.example.com/v1/items?api_key=replace_with_your_key
URLs can enter browser history, proxy and server logs, analytics systems, referrer data, tickets, and screenshots. Use a header or the provider’s client library when available. Google specifically recommends the x-goog-api-key header or a client library instead of query parameters (Google API-key best practices).
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
SDK and environment variable
export API_KEY="replace_with_your_key"
import os
api_key = os.environ["API_KEY"]
Environment variables avoid hard-coding a value in a source file, but they are not automatically secure. They can still leak through shell history, process inspection, CI output, crash reports, logs, or an incorrectly configured deployment system.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Are API keys secrets?
It depends on the key type and the provider. Treat a key as a secret whenever the provider says it is secret or whenever possession of it could enable meaningful access, charges, data access, or resource creation.
| Key type | Usually exposed to clients? | Recommended handling |
|---|---|---|
| Secret key | No | Keep on a trusted server, worker, or protected deployment system. |
| Publishable or public key | Sometimes | Expose only as intended; restrict by app, domain, API, operation, and quota. |
| Restricted key | Usually no | Prefer it over a broad secret key when an integration needs limited capabilities. |
| Test key | Depends | Keep test and live environments separate and label them clearly. |
A publishable key is not the same as an unrestricted key. It can still consume quota, cause billable usage, or be abused from an unauthorized website or application. Stripe says publishable keys are for client-side use, while secret keys must remain server-side (Stripe keys).
Authentication, authorization, and identification
Authentication asks who or what is making a request. Authorization asks what that caller is allowed to do. An API key can provide identification, support authentication, enforce authorization, track billing, enforce quotas, or combine several of these functions.
Google Cloud’s ordinary API keys associate requests with a project for billing and quota but do not authenticate a principal. Google’s provider-specific “authorization keys,” bound to service accounts, authenticate as that service account and behave more like long-lived bearer credentials (Google Cloud). OWASP warns not to rely on API keys alone for sensitive, critical, or high-value resources (OWASP REST Security Cheat Sheet).
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsAPI keys versus passwords, tokens, and OAuth
A secret API key resembles a password because whoever obtains it may be able to use it. It differs because it is normally issued to software, a project, account, subscription, or integration; is used programmatically; can often be restricted and rotated independently; and usually does not provide an interactive human login. Stripe describes secret keys as account credentials comparable to a username and password, while distinguishing them from publishable keys (Stripe key best practices).
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Credential | Typical purpose | Typical lifetime | Typical identity |
|---|---|---|---|
| API key | Identify an application or project; control usage, quota, or billing | Often long-lived, but provider-dependent | Application, project, account, subscription, or service |
| OAuth access token | Delegated access to resources within scopes | Often short-lived, but provider-dependent | User or client acting within granted scopes |
| Service-account or workload credential | Let an automated workload act as a service identity | Varies; short-lived is preferred where available | Service or workload |
| Password | Human account login | Until changed or expired | Human user |
| Request signature | Prove possession of signing material and protect request integrity | Per request or time-limited | Signing client or account |
“Token” is a broad term. Some providers call API keys tokens; others distinguish keys from OAuth tokens, personal access tokens, and signed credentials.
When an API key is appropriate
- The provider specifically expects one.
- The integration is application- or project-level rather than user-level.
- User consent and delegated access are unnecessary.
- The key can remain server-side or is explicitly publishable and restricted.
- Identification, billing, quota, and simple access control are the main requirements.
When OAuth is a better fit
- A user must authorize access to their data.
- Each user needs different scopes or permissions.
- The application acts on behalf of many users.
- Access tokens should expire independently of a password.
- The provider supports consent, revocation, and refresh-token workflows.
OAuth is not automatically safer for every workload; it solves delegated user authorization and adds implementation complexity.
Can an API key go in frontend or mobile code?
A client cannot keep a secret. Anything shipped in browser JavaScript, HTML, a mobile package, or a desktop application can potentially be extracted.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Use a client-side key only when the provider designed it for that purpose and supports restrictions. Keep secret operations behind your backend:
Browser or mobile app
|
v
Your backend stores and uses the secret key
|
v
Third-party API
Mobile applications should use publishable or restricted credentials, app restrictions, quotas, and a backend proxy for secret operations. User authentication may still be required.
How to store API keys safely
- Use a secret manager, encrypted configuration system, or protected deployment secret.
- Do not hard-code secrets in source code or commit them to Git, including private repositories.
- Keep development, test, and production keys separate.
- Grant access only to the people and systems that need it.
- Choose the narrowest API, endpoint, resource, and operation permissions available.
- Apply IP, referrer, application, API, environment, expiration, and quota restrictions where supported.
- Use HTTPS for transmission.
- Redact headers, query strings, request bodies, errors, CI logs, screenshots, and support tickets.
- Monitor usage and alert on unusual requests, charges, data access, or volume.
- Rotate keys after exposure, personnel changes, vendor changes, or according to your risk policy; there is no universal rotation interval.
- Delete unused keys.
Google recommends keeping keys outside the source tree, applying API and application restrictions, monitoring use, deleting unneeded keys, and rotating keys (Google credential security guidance). GitHub recommends encrypted repository or environment secrets and secret scanning (GitHub credential security). Stripe recommends secret-management tools, restricted keys, IP restrictions where practical, and rotation when people with access leave (Stripe best practices).
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What to do if an API key leaks
Assume the key is compromised. Do not merely delete the visible text.
Free tools Windows power users keep installed
One-click scans. No signup required.
- Revoke, disable, or delete the exposed key immediately.
- Create a replacement with the narrowest permissions and restrictions.
- Update application and deployment configuration, then verify the new key works.
- Remove the old value from source files, logs, tickets, and build artifacts where possible.
- Search repository history, forks, caches, CI systems, images, and backups for copies.
- Review API, billing, authentication, and audit logs for unauthorized activity.
- Check for unexpected data access, resource creation, charges, refunds, or usage spikes.
- Notify the provider if abuse may have occurred.
- Rotate related credentials stored beside the exposed key.
- Document the incident and improve restrictions, redaction, monitoring, and secret storage.
Deleting a secret from the latest Git commit does not remove it from repository history or clones. Google warns that exposed keys can cause unexpected charges or account compromise; Stripe warns that a stolen secret key may enable unauthorized charges, customer-data access, or integration disruption (Google; Stripe).
Common API-key errors
| Symptom | Likely meaning |
|---|---|
401 Unauthorized, “missing key,” or “invalid key” |
The credential is absent, malformed, revoked, expired, or not accepted by the endpoint. |
403 Forbidden or “permission denied” |
The key is recognized but lacks the required permission, API access, project authorization, or origin/IP allowance. |
429 Too Many Requests |
Rate or quota limits were exceeded. OWASP recommends 429 for excessive request rates, but response details vary by provider. |
| “Billing not enabled” or “quota exceeded” | The associated project or account has a billing, quota, or usage problem. |
Check the provider’s exact error body, endpoint documentation, enabled APIs, restrictions, billing status, and environment before replacing a key.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What API-key restrictions can do
- API restrictions: allow only named APIs.
- IP restrictions: allow known server addresses.
- HTTP referrer restrictions: allow approved websites.
- Application restrictions: bind a key to a mobile app or application identity.
- Permission restrictions: allow only selected operations or resources.
- Environment separation: prevent test credentials from being used in production.
- Expiration and quotas: limit useful lifetime or maximum spend and volume.
No restriction is perfect. Dynamic networks complicate IP allowlists, referrer restrictions are unsuitable for server-side secrets, and mobile or browser credentials are inherently more exposed.
What API keys do not protect against
An API key does not automatically stop broken object-level authorization, one user accessing another user’s records, excessive data exposure, injection, server-side request forgery, replay of a stolen key, abuse by a compromised legitimate client, weak rate limiting, or credential leakage through logs and URLs. Resource-level authorization, input validation, secure transport, monitoring, and least privilege remain necessary.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWhen stronger credentials are warranted
Consider OAuth 2.0, OpenID Connect, mutual TLS, signed requests, short-lived credentials, workload identity, managed identities, service accounts, or temporary security credentials when users must grant access, permissions are user-specific, credentials need rapid expiry, request integrity matters, clients cannot safely store secrets, or several services need separate audit identities.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Google recommends IAM policies and short-lived service-account credentials instead of authorization keys for most production use cases (Google guidance). AWS recommends short-term keys or temporary security credentials where possible; its service-specific documentation notes that short-term keys may be valid for up to 12 hours or the remaining console-session duration, whichever is shorter (AWS service API keys).
Do you need a secret manager?
For one local experiment, a protected environment variable or your hosting platform’s secret store may be enough. A dedicated manager becomes more valuable when you have production credentials, multiple environments, several developers or services, CI/CD pipelines, rotation requirements, audit requirements, or many third-party integrations.
| Service | Useful for | Pricing or fit note |
|---|---|---|
| AWS Secrets Manager | AWS applications needing IAM integration, retrieval, and managed rotation | AWS’s pricing page shows a US example of $0.40 per secret per month and $0.05 per 10,000 API calls; region and pricing can change (pricing). |
| Google Cloud Secret Manager | Google Cloud workloads using IAM, Cloud Run, GKE, or service accounts | Google documents free monthly allowances for six active secret versions, 10,000 access operations, and three rotation notifications; usage above those limits is billed (pricing). |
| Azure Key Vault | Azure identity, certificates, cryptographic keys, and secrets | Operations are transaction-priced, with separate premium/HSM considerations; estimates vary by region, agreement, currency, and offer (pricing). |
| HashiCorp Vault | Multi-cloud, hybrid, and platform teams needing centralized policy or dynamic credentials | Commercial tiers and deployment options should be checked on the official pricing page. |
| 1Password Secrets Automation | Teams already using 1Password that want machine-accessible application secrets | Verify the current business or developer plan for your geography and account type (business pricing). |
Frequently Asked Questions
Can I share an API key with a contractor or vendor?
Avoid sharing a broad account-wide secret. Use a restricted key, OAuth connection, separate integration identity, or dedicated account when the provider supports one.
Is an API key encrypted?
HTTPS protects a key while it travels between a client and server when configured correctly. It does not protect a key stored in source code, logs, browser history, memory dumps, or a compromised device.
What is the difference between an API key and a webhook secret?
An API key authorizes outbound calls to an API. A webhook signing secret lets your application verify that an incoming webhook was signed by the provider; it is a separate credential.
Do all APIs require an API key?
No. Some APIs are public, use OAuth, require signed requests or mutual TLS, or use cloud workload identities. Follow the provider’s authentication documentation.
The Bottom Line
Use an API key exactly as its provider documents, but assume a secret key is a bearer credential: keep it server-side, restrict it, redact it from logs, monitor its use, and revoke and replace it immediately if exposed. Choose OAuth or short-lived service credentials when the integration needs user delegation, fine-grained identity, or stronger protection than a static key can provide.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

