nommiopen nommi

Glossary / Building your app / API key (application programming interface key)

Building your app

API key (application programming interface key)

An API key is a password your app uses to reach another service through its API (application programming interface), and anyone who copies a secret key can act as you.

Also called API token, secret key

Secret keys belong on your server, not in code that runs in the visitor's browser, where anyone can read them. If one leaks, replace it. Some services also give a public key meant to sit in the browser; the service's setup page says which is which.

When this shows up

Example, not a real founder: you get a surprise usage warning from a service your app calls. The key had been placed in code that runs in the browser, and someone copied it.

What to do next

Search your app's browser-side code for any secret keys and move each one into server-side settings, often called environment variables. Then replace any key that was ever exposed.

Go deeper

Is my AI-built app safe to launch? A ten-minute check

Read the guide