What Is an API Key? A Plain-English Guide (With Claude and ChatGPT Examples)
An API key is a password for software. What API keys are, how they're different from your login, how to get one for Claude or OpenAI, where to keep it, why it must never be in your frontend code, and what to do if one leaks.
Sooner or later, a tutorial or an AI tool will ask you for an API key. It looks like a long random string — something like sk-ant-api03-... — and it's surprisingly powerful. Here's what it is and how to handle one safely.
The short version
An API key is a password for a program. When your app talks to another service — Claude, OpenAI, Stripe, an email provider — it can't log in with a username and password like a person. Instead it sends an API key with every request. The service checks the key and knows who is calling, what they're allowed to do, and who to bill.
That last part is why API keys matter so much: anyone who has your key can use the service as you, on your bill.
(New to APIs? What is an API? explains the basics.)
API key vs your account login
| Your login | An API key | |
|---|---|---|
| Used by | You, in a browser | Your code |
| Typed in | A login form | A config file or environment variable |
| Usually has 2FA | Yes | No — the key alone is enough |
| You can have | One | Many (one per app is good practice) |
Because an API key works with no second factor, a leaked key is often worse than a leaked password.
Getting a key for an AI service
For Claude, you create API keys in the Claude Console (platform.claude.com) under API keys. For OpenAI, it's the API keys page of the OpenAI platform. Either way:
- You create the key and give it a name ("reading-list-app-production").
- The full key is shown once. Copy it straight into somewhere safe.
- Usage is billed per token to that account — separately from any chat subscription. A Claude Pro or ChatGPT Plus subscription doesn't include API usage. (What are tokens?)
Set a spending limit on the account straight away. If something goes wrong, the limit is your safety net.
Where an API key should live
On a server, in an environment variable. Not in your code, and never in anything that runs in a visitor's browser.
# .env — on the server, never committed to git
ANTHROPIC_API_KEY=sk-ant-...
Your code reads it at runtime (process.env.ANTHROPIC_API_KEY in Node.js). The .env file is listed in .gitignore so it never reaches GitHub. See What is an environment variable?.
The mistake AI-built apps make most
Frontend code — anything in React, Vite or the browser — is downloaded by every visitor. If a secret key is in it, anyone can open the browser's developer tools and read it. Variables starting with VITE_, NEXT_PUBLIC_ or REACT_APP_ are deliberately bundled into the browser.
So the browser must never call Claude or OpenAI directly with your key. Instead:
- The browser calls your backend (
/api/chat). - Your backend adds the key and calls the AI service.
- Your backend sends the answer back.
How to keep API keys out of an AI-built app covers this in detail.
Publishable keys are different
Some services give you two kinds of key. Stripe has a publishable key (safe in the browser) and a secret key (server only). Supabase now has publishable keys (sb_publishable_...) and secret keys (sb_secret_...), replacing the older anon and service_role keys. The rule: if it's called secret, private or service-role, it's server-only.
Good habits
- One key per app and environment. Separate keys for development and production mean one leak only needs one rotation.
- Least privilege. If the service lets you limit a key's permissions, do.
- Name keys clearly so you know what breaks when you revoke one.
- Rotate keys occasionally, and immediately when someone with access leaves.
- Set spending limits and alerts on paid APIs.
If a key leaks
Revoke it first, then investigate. Deleting the commit isn't enough — bots scan GitHub for keys within minutes. Follow I leaked an API key. What now?.
The summary
- An API key is a password your code uses to call another service — and it's tied to your bill.
- Keep it in a server-side environment variable, out of git, and out of the browser.
- AI API usage is billed separately from chat subscriptions; set a spending limit.
- Leaked? Revoke first.
EasySpawn stores each project's secrets as server-side environment variables on its own isolated server, so your API keys reach your backend and never your visitors' browsers. See how it works or join the waitlist.
Related: What Is an SDK? · How to Add an AI Chatbot to Your App · Secrets Management Beyond .env Files · How to Stop Bots From Running Up Your AI App's Bill
Keep reading
Why Does AI Hallucinate? And How to Reduce It in Your App
AI models sometimes state false things with complete confidence. Why it happens — they predict plausible text rather than look up facts — the kinds of hallucination you'll meet in coding and apps, and practical ways to reduce it: grounding, tools, structure, checks and room to say 'I don't know'.
What Is Cloudflare? What It Does When You Put Your Site Behind It
Cloudflare sits between your visitors and your server: DNS, a CDN, free SSL, DDoS protection and a firewall. What changes when you turn on the orange cloud, what it costs, what it can break, and whether a small app needs it.