EMZETT.
Login

API Keys

In short: An API key is a secret key with which a program identifies itself to an API.

In more detail: It identifies the caller and allows access and billing.

In Depth

Handling

  • Never store it in source code or public repositories (GitHub).
  • Keep it in environment variables or secrets (.env files).
  • Own keys per application with minimal rights, renew regularly.
  • Revoke immediately if published.

Danger

Stolen keys lead to misuse and high costs (resource abuse). See APIs, environment variables.

See also: APIs, .env Files, GitHub, Environment Variables