Key Takeaways
- An app ID or client ID is public; the secret is what proves ownership.
- Keep secrets on the server, in environment variables or a secrets manager, never in front-end code or Git.
- Chat platforms use secrets to sign webhooks: verify the signature on every request.
- If a secret leaks, rotate it in the developer console and redeploy.
What Is an API Secret?
An API secret is the private half of an app's credentials. The public half - an app ID, client ID or API key - says which app is calling; the secret proves the call really comes from you. Platforms call it different things: app secret, client secret, signing secret, secret token. Whoever holds it can act as your app.
Where Chat Platforms Use Secrets
| Platform | Secret | Used for |
|---|---|---|
| Meta (WhatsApp, Messenger, Instagram) | App Secret | Signing webhook payloads (the X-Hub-Signature-256 header) and server-side calls |
| Slack | Signing secret | Verifying that requests to your app came from Slack |
| Telegram | secret_token set with setWebhook | Echoed in X-Telegram-Bot-Api-Secret-Token so your endpoint can reject fake updates |
| OAuth providers | Client secret | Exchanging an authorisation code for tokens |
The Telegram webhook checker lets you set a secret token without writing code.
Keeping a Secret Secret
- Store it in environment variables or a secrets manager on the server.
- Never ship it in a mobile app, a browser bundle or a public repository.
- Verify webhook signatures on every request and reject anything that fails.
- Rotate it on a schedule and immediately if it may have leaked, then redeploy.
Frequently Asked Questions
What is the difference between an API key and an API secret?
Where should I store an API secret?
What is a webhook signing secret?
What should I do if my API secret leaks?
Is a bot token an API secret?
Free plan, no credit card required.