Building your app
API key (application programming interface key)
An API key is a password your app uses to reach another service through its API (application programming interface), and anyone who copies a secret key can act as you.
Also called API token, secret key
Secret keys belong on your server, not in code that runs in the visitor's browser, where anyone can read them. If one leaks, replace it. Some services also give a public key meant to sit in the browser; the service's setup page says which is which.
When this shows up
Example, not a real founder: you get a surprise usage warning from a service your app calls. The key had been placed in code that runs in the browser, and someone copied it.
What to do next
Search your app's browser-side code for any secret keys and move each one into server-side settings, often called environment variables. Then replace any key that was ever exposed.