API Key
The secret credential that authenticates and bills your API calls — and must never reach a browser.
An API key identifies your account to the provider. Anyone holding it can spend your budget and read your usage, so keys belong on a server or in a secrets manager, never in front-end code or a public repository. Rotate them and scope them wherever the provider allows.
In practice: A key committed to a public repo gets found and used within minutes.
Where this comes up
- Best AI Coding Agents in 2026: Top Tools by Use Case
- Claude Commerce Agents: Anthropic's Open-Source Blueprint for AI Shopping Assistants and Merchant Agents
- Claude Usage Limits: How They Work and How to Stop Hitting Them
- Gemini Deep Research Limit: What Caps Your Runs and How to Work Within It
- Gemini Usage Limits: How the Quotas Work and What Trips Them
- How to Become an Automation Engineer: Role Map, Skills, and a Portfolio Automation