API Keys
In short: An API key is a secret key with which a program identifies itself to an API.
In more detail: It identifies the caller and allows access and billing.
In Depth
Handling
- Never store it in source code or public repositories (GitHub).
- Keep it in environment variables or secrets (.env files).
- Own keys per application with minimal rights, renew regularly.
- Revoke immediately if published.
Danger
Stolen keys lead to misuse and high costs (resource abuse). See APIs, environment variables.
See also: APIs, .env Files, GitHub, Environment Variables