Skip to main content

AI coding · Security

API Key

Also called: Secret key, API token, Access key

A secret string that identifies and bills you when you call a large model or third-party service. It's basically your account password. If it leaks, other people can spend your money.

In detail

An API key is like a key card linked to your credit card. Whoever gets it can use the service in your name, and the bill goes to you. You usually need one when your code calls large models, maps, payments, and similar services.

The most common accident is hardcoding the key in frontend code or committing it to a public Git repo. Frontend code gets downloaded in full to the user's browser, and anyone can see it by opening developer tools. The right way: keep the key only on the server (a backend API or a server-side function), read it from an Environment Variable, and have the frontend call only your own backend API.

If you think it's leaked, go to the provider's dashboard right away, revoke the old key, and create a new one. Just deleting it from the code isn't enough, because it's still in your Git history.

Developer info
Term ID
ai-api-key
DOM selectors
No DOM cues. This concept isn't detected directly on a page.
Priority
1 · when several match at the same level, the higher priority wins
Version
v1 · updated Sep 29, 2026