Sitelet https://funapi.dev/glossary/api-key

API key

An API key is the simplest credential an API can issue: a long random string tied to an account or project, sent with every request — usually in a header such as X-API-Key, sometimes in the query string. It identifies who is calling, for billing, quotas and access control, but carries no expiry or scope of its own unless the server attaches them.

How it works

The server looks the key up on each request, rejects unknown ones with 401 and applies that key's quota and permissions. Keys are typically created in a dashboard, can be rotated by issuing a new one before revoking the old, and are often restricted to particular IP ranges, referrers or endpoints.

The misconception

That a key in a query string is as safe as one in a header. URLs are written to server logs, proxy logs and browser history and can leak through the Referer header; a header is not secret either, but it does not end up in nearly as many places.

Try it here

The Cargo Tracking API requires X-API-Key on its writes — POST /cargo/v1/shipments and the state-machine transitions — while its reads are open, so the same API shows both sides.

Other terms

All glossary terms · Testing techniques · All 39 mock REST APIs

Last updated