Skip to content
estudIA

AI glossary

API key

A secret string that identifies you to an AI provider’s API, so it can authorise your requests and bill your account.

When your code calls a model, it sends the key with each request. Anyone who has the key can spend your money, so treat it like a password: keep it in an environment variable or a secrets manager, never in code you publish or in a website’s front end.

If a key leaks, revoke it in the provider’s console and create a new one. Most consoles let you set spending limits per key.

Example: A developer accidentally pushes a file containing their key to a public repository. Some programs scan repositories for keys, so someone could find it quickly and make thousands of requests at their expense.

In practice

  • Use a different key for each project or environment, so you can revoke one without stopping the rest.
  • Never put it in browser or mobile app code; make the calls from your server.
  • Add the file where you keep it, such as .env, to .gitignore.

In how to install an MCP server you will see how to read keys from environment variables.

Related terms

Learn more

← Back to the glossary