An API key is the simplest credential an API can issue: a long random string tied to an account or project, sent with every request — usually in a header such as X-API-Key, sometimes in the query string. It identifies who is calling, for billing, quotas and access control, but carries no expiry or scope of its own unless the server attaches them.
The server looks the key up on each request, rejects unknown ones with 401 and applies that key's quota and permissions. Keys are typically created in a dashboard, can be rotated by issuing a new one before revoking the old, and are often restricted to particular IP ranges, referrers or endpoints.
That a key in a query string is as safe as one in a header. URLs are written to server logs, proxy logs and browser history and can leak through the Referer header; a header is not secret either, but it does not end up in nearly as many places.
The Cargo Tracking API requires X-API-Key on its writes — POST /cargo/v1/shipments and the state-machine transitions — while its reads are open, so the same API shows both sides.
All glossary terms · Testing techniques · All 39 mock REST APIs
Last updated