Safety & permissions

API key

Also called API keys.

An API key is a credential an application sends so an API can identify or authorize the caller.

Example

A server sends its API key with a request to a maps API. The key stays on the server. The browser page never includes it.

Why it matters

A key is a secret. It should not appear in a public page, a screenshot, or a chat transcript. A key identifies the caller the provider issued it to. It is not the same object as an AI token.

Common confusion

An API key is a secret credential. It is not an AI token, and it is not safe to paste into a prompt.

Sources

Updated September 30, 2026.

Cookie preferences