No. 073·noun·also called secret key, access key, credentials

API key

A long secret code that lets your app use another service, like a password for software.

SPECIMEN · DIAGRAM · FLOW
DataBackend secretssk_live_•••
AppBackend
ServiceStripe
readcall with key
Definition

What it is

An API key identifies your app to a service like Stripe or an email provider, so it knows who's calling and who to bill. It looks like a long random string.

Treat it like a password: it belongs in the backend's secret settings (often called environment variables), never in frontend code or a screenshot. Anyone with it can act as you.

Services usually give separate test and live keys, so you can build without real charges.

Say it like a builder

How to ask for it

Vague

“Here's my Stripe key, put it in.”

Precise

“Store my Stripe API key as a backend secret (separate test and live values), use it only in backend code, and never send it to the browser or write it into the codebase.”

Why it works

"Put it in" could land the key in public code; naming it an API key with storage rules keeps it secret.

In the wild

You've seen this in

  • SStripe's "sk_live_…" secret keys
  • DAn OpenAI key in a developer dashboard
  • TTwilio account credentials
Usage note

Often confused with