API Key
- In Turkish
- API Anahtarı
In short
An API key is a unique secret string that identifies an application or project when it calls an API, used to control access, track usage, and apply rate limits.
What is an API key?
An API key is a long, random string that a service issues to a developer or application. The client includes the key with each request, usually in an HTTP header such as Authorization or X-API-Key, and the server looks it up to decide which project the request belongs to, whether it is allowed, and how much of its quota it has used.
API keys are popular because they are simple: there is no login flow, which makes them convenient for server-to-server calls, scripts, and developer services such as payment, mapping, email, and AI model APIs. Providers use them to meter billing, enforce rate limits, and switch off access for a single project without affecting others.
An API key works like a building key card: whoever holds the card gets in, no matter who they are. That is its main weakness, because a key identifies a project, not a person, and anyone who copies it can use it. Keys are therefore different from OAuth access tokens, which are short-lived, tied to a specific user's consent, and limited by scopes.
To protect API keys, keep them on the server and out of front-end code and mobile apps, where anyone can extract them. Load them from environment variables or a secrets manager, never commit them to Git, and turn on secret scanning to catch leaks. Give each key only the permissions it needs, restrict it by IP address or domain when the provider allows, store only a hash of keys you issue yourself, and rotate or revoke a key immediately if it may have been exposed.
Key takeaways
- An API key identifies the calling application or project.
- It is sent with each request, usually in an HTTP header.
- Anyone who has the key can use it, so treat it like a password.
- Keep keys on the server, out of Git and client-side code.
- Limit permissions, and rotate or revoke keys that may have leaked.
Example
// Load the key from the environment; never hard-code it in source files
const apiKey = process.env.WEATHER_API_KEY;
// Call the API from the server, sending the key in a header, not the URL
const res = await fetch("https://api.example.com/v1/forecast?city=Paris", {
headers: { Authorization: `Bearer ${apiKey}` },
});
if (res.status === 401) {
throw new Error("API key is missing, invalid, or revoked");
}
const forecast = await res.json();Readers ask
What is the difference between an API key and an OAuth token?
An API key is a long-lived secret that identifies an application or project. An OAuth access token is usually short-lived, represents a specific user's permission, and is limited to the scopes that user approved.
Is it safe to put an API key in front-end JavaScript?
Not for secret keys. Anything shipped to a browser or mobile app can be read by users, so secret keys belong on a server that calls the API on the client's behalf; some providers issue publishable keys meant for front-end use, which should still be restricted by domain.
What should I do if I leaked an API key?
Revoke or rotate the key immediately in the provider's dashboard, then replace it wherever it is used. Deleting it in a later Git commit is not enough, because it remains in the repository history and may already have been copied by automated scanners.
See also
- APIBackend & APIs, p. 2An API is a set of rules that lets one piece of software request data or actions from another in a predictable, documented way.
- AuthenticationSecurity, p. 2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- Environment VariableDevOps & Cloud, p. 20An environment variable is a named value set outside a program, by the operating system or runtime, that the program reads to configure its behavior.
- Rate LimitingBackend & APIs, p. 37Rate limiting is a technique that caps how many requests a client can make to a server or API within a time window, protecting it from abuse and overload.
- OAuthSecurity, p. 22OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
- .gitignoreVersion Control, p. 1A .gitignore file is a plain-text file listing patterns for files and folders Git should not track, such as dependencies, build output, logs, and secrets.
Spotted a mistake or something missing on this page?Suggest an edit