Key Takeaways
- An API key identifies the application making a request and is checked on every call.
- It is sent in a header (such as Authorization: Bearer ...) or sometimes a query parameter.
- Many API keys are full credentials: anyone holding one can spend your quota, so treat them as secrets.
- Restrict, rotate and store keys on the server; never ship them in front-end code or Git.
What Is an API Key?
An API key is a long, unique string - for example sk-... or AIza... - that an application includes with each request to an API. The service looks it up to see who is calling, which features that caller may use, and how much of its quota or bill the request counts against. It works like a membership card for software.
How an API Key Works
- You create a key in the provider's dashboard, often choosing a name and the permissions it gets.
- Your server sends it with every request, usually in a header:
Authorization: Bearer YOUR_KEYor a custom one such asx-api-key. - The API checks the key, applies rate limits and permissions, then answers or rejects the call with an error such as 401 Unauthorized or 403 Forbidden.
| Service | What the key is called | How it is sent |
|---|---|---|
| OpenAI | API key (secret key) | Authorization: Bearer header |
| Google Maps / Google Cloud | API key | key= parameter or header, restricted by site or app |
| Telegram | Bot token | Inside the request URL: /bot<token>/method |
| Stripe | Publishable key and secret key | Publishable in the browser, secret only on the server |
API Key vs API Secret vs OAuth Token
- API key: identifies the calling app. Some (like Stripe's publishable key or a restricted Google Maps key) are meant to be visible; most are not.
- API secret: a private value that proves the call comes from you, often used to sign requests or webhooks.
- OAuth token: short-lived access granted by a user, scoped to what they approved, instead of a long-lived key for the whole account.
An app ID sits beside these as the public name of your app.
Keeping API Keys Safe
- Keep secret keys on the server, in environment variables or a secrets manager.
- Never put them in front-end JavaScript, mobile apps, screenshots or public repositories; bots scan GitHub for leaked keys within minutes.
- Restrict each key to the APIs, websites, IP addresses or permissions it needs.
- Use a separate key per app and environment, and rotate keys on a schedule and immediately after a leak.
- Set usage alerts or spending caps so a stolen key cannot run up a large bill.
Checking a Telegram bot token? The Telegram webhook checker confirms whether a token is valid and where its updates go.
Frequently Asked Questions
What is an API key in simple terms?
What does an API key look like?
How do I get an API key?
Is an API key the same as a password?
What should I do if my API key is leaked?
Free plan, no credit card required.