Key
In short: The secret (or partly secret) value that an encryption algorithm needs, alongside the data itself, to turn plaintext into ciphertext or back again.
In more detail: The security of modern cryptography rests entirely on keeping the key secret, not on keeping the algorithm secret (Kerckhoffs’s principle). With symmetric encryption there’s one shared key, with asymmetric encryption a key pair of public and private key. Longer keys mean (up to a point) more security, since brute-force attacks become exponentially more expensive.
In Depth
Kerckhoffs’s principle from the 19th century is still the basic rule of modern cryptography today: an encryption system must remain secure even if the attacker knows the entire algorithm — only the key itself is allowed to be secret. AES, RSA and the SHA family are all publicly documented, openly inspectable algorithms; their security relies exclusively on an attacker not knowing the correct key and not being able to guess or compute it in a practical amount of time.
Key length directly determines how many possible keys an attacker would have to try in the worst case:
128-bit key: 2^128 ≈ 3.4 × 10^38 possible combinations
256-bit key: 2^256 ≈ 1.2 × 10^77 possible combinations
Every additional bit doubles the effort needed for a complete brute-force attack — even 128 bits is considered practically unbreakable with today’s and foreseeable future computing power; 256 bits is often chosen for data that needs particularly long-term protection, also as a safety margin against possible future breakthroughs (such as quantum computers, which could theoretically break classical encryption faster than today’s computers).
Important: “key” in cryptography doesn’t necessarily mean a human-readable password — it’s usually a randomly generated sequence of bits, which from a cryptographic point of view is considerably more secure than a human-chosen, often predictable password.
Key management as a practical challenge
In practice, the cryptography itself isn’t the weakest point — managing the keys around it is. A mathematically perfectly secure algorithm is useless if the key is stored insecurely, accidentally committed to a public code repository, or lost on an unencrypted USB stick. Larger organisations therefore rely on dedicated key management systems: hardware security modules (HSMs) store particularly critical keys in special, tamper-resistant hardware from which the key itself can never be extracted — all cryptographic operations run internally inside the HSM, only the result leaves the device. Cloud providers offer comparable managed services (e.g. AWS KMS, Azure Key Vault) for applications that don’t want to run their own HSM hardware.
Key rotation and expiry dates
For security reasons, keys are often not used indefinitely but replaced regularly (“rotation”) — the longer a key is in use, the greater the cumulative risk that it will be compromised at some point (stolen, accidentally leaked, made vulnerable by advancing computing power), and the greater the damage if that happens, since more data protected by it would be affected. TLS certificates therefore have an expiry date by default (today usually a maximum of 398 days), API keys can be manually revoked and regenerated at any time in good systems, and session keys are automatically discarded after every single connection anyway.
See also: Key-lock principle, Encryption