Lesson 14 / 24

API Keys

The simplest way to identify a calling application.

A shared secret per client

An API key is a long, random string issued per application. It identifies which app is calling (for rate limiting, billing, revocation) — it's usually not meant to identify an individual end user.

Never put it in the URL

A key in a query string ends up in server logs, browser history, and referer headers. Send it as a header instead: X-API-Key: ... or Authorization: Bearer ....

Keys authenticate apps, not users

API keys are a weak fit when you need to know which user is acting, or need permissions that vary per user — that's where OAuth 2.0 and JWTs come in.