AI glossary
API key
A secret string that identifies you to an AI provider’s API, so it can authorise your requests and bill your account.
When your code calls a model, it sends the key with each request. Anyone who has the key can spend your money, so treat it like a password: keep it in an environment variable or a secrets manager, never in code you publish or in a website’s front end.
If a key leaks, revoke it in the provider’s console and create a new one. Most consoles let you set spending limits per key.
Example: A developer accidentally pushes a file containing their key to a public repository. Some programs scan repositories for keys, so someone could find it quickly and make thousands of requests at their expense.
In practice
- Use a different key for each project or environment, so you can revoke one without stopping the rest.
- Never put it in browser or mobile app code; make the calls from your server.
- Add the file where you keep it, such as
.env, to.gitignore.
In how to install an MCP server you will see how to read keys from environment variables.

