Skip to main content

API Key

In Turkish
API Anahtarı
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/api-key

In short

An API key is a unique secret string that identifies an application or project when it calls an API, used to control access, track usage, and apply rate limits.

What is an API key?

An API key is a long, random string that a service issues to a developer or application. The client includes the key with each request, usually in an HTTP header such as Authorization or X-API-Key, and the server looks it up to decide which project the request belongs to, whether it is allowed, and how much of its quota it has used.

API keys are popular because they are simple: there is no login flow, which makes them convenient for server-to-server calls, scripts, and developer services such as payment, mapping, email, and AI model APIs. Providers use them to meter billing, enforce rate limits, and switch off access for a single project without affecting others.

An API key works like a building key card: whoever holds the card gets in, no matter who they are. That is its main weakness, because a key identifies a project, not a person, and anyone who copies it can use it. Keys are therefore different from OAuth access tokens, which are short-lived, tied to a specific user's consent, and limited by scopes.

To protect API keys, keep them on the server and out of front-end code and mobile apps, where anyone can extract them. Load them from environment variables or a secrets manager, never commit them to Git, and turn on secret scanning to catch leaks. Give each key only the permissions it needs, restrict it by IP address or domain when the provider allows, store only a hash of keys you issue yourself, and rotate or revoke a key immediately if it may have been exposed.

Key takeaways

  • An API key identifies the calling application or project.
  • It is sent with each request, usually in an HTTP header.
  • Anyone who has the key can use it, so treat it like a password.
  • Keep keys on the server, out of Git and client-side code.
  • Limit permissions, and rotate or revoke keys that may have leaked.

Example

Calling an API with a key from the serverjavascript
// Load the key from the environment; never hard-code it in source files
const apiKey = process.env.WEATHER_API_KEY;

// Call the API from the server, sending the key in a header, not the URL
const res = await fetch("https://api.example.com/v1/forecast?city=Paris", {
  headers: { Authorization: `Bearer ${apiKey}` },
});

if (res.status === 401) {
  throw new Error("API key is missing, invalid, or revoked");
}
const forecast = await res.json();

Readers ask

What is the difference between an API key and an OAuth token?

An API key is a long-lived secret that identifies an application or project. An OAuth access token is usually short-lived, represents a specific user's permission, and is limited to the scopes that user approved.

Is it safe to put an API key in front-end JavaScript?

Not for secret keys. Anything shipped to a browser or mobile app can be read by users, so secret keys belong on a server that calls the API on the client's behalf; some providers issue publishable keys meant for front-end use, which should still be restricted by domain.

What should I do if I leaked an API key?

Revoke or rotate the key immediately in the provider's dashboard, then replace it wherever it is used. Deleting it in a later Git commit is not enough, because it remains in the repository history and may already have been copied by automated scanners.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings