# API Keys, Environment Variables and Safe Setup — Claude API / OpenAI API Basics

Source: https://www.geekswithgeeks.com/en/llm-apis/b-keys

> Create, store and use keys without leaking them.

## A key is a password with a credit card attached

An **API key** identifies and bills your account. Anyone who has it can spend your money and access your data, so treat it like a password. Rules: create **separate keys** per application and environment; keep keys in **environment variables** or a **secrets manager**, never in source code, notebooks, screenshots or chat messages; **never ship keys in browser or mobile apps** (call the API from your own backend, which authenticates your users); set **spend limits and alerts** in the provider console; **rotate** keys on a schedule and immediately if one might have leaked; and add `.env` to `.gitignore`. SDKs read standard variables (such as `ANTHROPIC_API_KEY` and `OPENAI_API_KEY`) automatically, so you rarely type a key in code.

## Reading a key safely (illustrative)

Fail early with a clear message if the variable is missing. Not run here because it needs your real environment.

```python
import os, sys

key = os.environ.get("ANTHROPIC_API_KEY")
if not key:
    sys.exit("ANTHROPIC_API_KEY is not set. Export it or load it from your secrets manager.")

# Never print the key. If you must log it for debugging, show only a prefix/suffix:
print("key loaded:", key[:4] + "..." + key[-2:])
```

## A leaked key: act within minutes

Revoke it in the console first, create a new one, then check usage logs for abuse. Deleting the commit is not enough because the key may already be copied.

**Quiz:** Where should an API key live in a web application?

- [x] On your backend, in an environment variable or secrets manager
- [ ] In the browser JavaScript
- [ ] In a public GitHub repository
- [ ] In the page HTML comments

*Answer:* On your backend, in an environment variable or secrets manager. Anything shipped to a client can be extracted; keep keys server-side.
