Lesson 15 / 25
API Keys
Use API keys to identify calling applications, send them in headers and know when OAuth or JWT is a better fit.
A shared secret per client
An API key is a long, random string issued per application. It identifies which app is calling (for rate limiting, billing, revocation) — it's usually not meant to identify an individual end user.
Never put it in the URL
A key in a query string ends up in server logs, browser history, and referer headers. Send it as a header instead: X-API-Key: ... or Authorization: Bearer ....
Keys authenticate apps, not users
API keys are a weak fit when you need to know which user is acting, or need permissions that vary per user — that's where OAuth 2.0 and JWTs come in.