Skip to main content
Technical

API Key

An API key is a unique string an application sends with each request to an API, so the service can identify the caller, apply limits and decide what it may access.

Oct 6, 2026
5 min read
Conferbot Team

Key Takeaways

  • An API key identifies the application making a request and is checked on every call.
  • It is sent in a header (such as Authorization: Bearer ...) or sometimes a query parameter.
  • Many API keys are full credentials: anyone holding one can spend your quota, so treat them as secrets.
  • Restrict, rotate and store keys on the server; never ship them in front-end code or Git.

What Is an API Key?

An API key is a long, unique string - for example sk-... or AIza... - that an application includes with each request to an API. The service looks it up to see who is calling, which features that caller may use, and how much of its quota or bill the request counts against. It works like a membership card for software.

How an API Key Works

  1. You create a key in the provider's dashboard, often choosing a name and the permissions it gets.
  2. Your server sends it with every request, usually in a header: Authorization: Bearer YOUR_KEY or a custom one such as x-api-key.
  3. The API checks the key, applies rate limits and permissions, then answers or rejects the call with an error such as 401 Unauthorized or 403 Forbidden.
ServiceWhat the key is calledHow it is sent
OpenAIAPI key (secret key)Authorization: Bearer header
Google Maps / Google CloudAPI keykey= parameter or header, restricted by site or app
TelegramBot tokenInside the request URL: /bot<token>/method
StripePublishable key and secret keyPublishable in the browser, secret only on the server

API Key vs API Secret vs OAuth Token

  • API key: identifies the calling app. Some (like Stripe's publishable key or a restricted Google Maps key) are meant to be visible; most are not.
  • API secret: a private value that proves the call comes from you, often used to sign requests or webhooks.
  • OAuth token: short-lived access granted by a user, scoped to what they approved, instead of a long-lived key for the whole account.

An app ID sits beside these as the public name of your app.

Keeping API Keys Safe

  • Keep secret keys on the server, in environment variables or a secrets manager.
  • Never put them in front-end JavaScript, mobile apps, screenshots or public repositories; bots scan GitHub for leaked keys within minutes.
  • Restrict each key to the APIs, websites, IP addresses or permissions it needs.
  • Use a separate key per app and environment, and rotate keys on a schedule and immediately after a leak.
  • Set usage alerts or spending caps so a stolen key cannot run up a large bill.

Checking a Telegram bot token? The Telegram webhook checker confirms whether a token is valid and where its updates go.

Frequently Asked Questions

What is an API key in simple terms?
An API key is a password-like code that an app sends when it talks to another service's API. The service uses it to recognise the app, check what it is allowed to do and count its usage. Without a valid key, the request is rejected.
What does an API key look like?
Usually a long random string of letters and numbers, often with a prefix that shows the provider or type, such as sk- for OpenAI secret keys or AIza for Google keys. The exact format does not matter to you; copy it exactly and keep it private.
How do I get an API key?
Sign in to the provider's developer dashboard or console, open the API keys or credentials section and create a new key. Give it a descriptive name, limit its permissions if the provider allows, and copy it once into your server configuration, since many services only show the full key at creation.
Is an API key the same as a password?
It plays a similar role for software rather than people. A password signs a person in; an API key authenticates an application on every request. Like a password, a leaked key lets someone else act as you, so store it securely and replace it if it is exposed.
What should I do if my API key is leaked?
Revoke or rotate it in the provider's dashboard immediately, put the new key in your server configuration and redeploy. Then review usage and billing for calls you did not make, remove the key from any code or history where it appeared, and add restrictions to the new key.
Omnichannel Platform

One Chatbot,
Every Channel

Your chatbot works seamlessly across WhatsApp, Messenger, Slack, and 6 more platforms. Build once, deploy everywhere.

View All Channels
Conferbot
online
Hi! How can I help you today?
I need pricing info
Conferbot
Active now
Welcome! What are you looking for?
Book a demo
Sure! Pick a time slot:
#support
Conferbot
New ticket from Sarah: "Can't access dashboard"
Auto-resolved. Password reset link sent.
Free Chatbot Templates

Ready to Build Your
Chatbot?

Browse free templates for every industry and deploy in minutes. No coding required.

100% Free
No Code
2-Min Setup
Lead Generation
Capture & qualify leads
Customer Support
24/7 automated help
E-commerce
Boost online sales