API Key

An API key is a unique secret string that a client includes with requests to an API so the provider can identify which project or account is calling, apply permissions and usage limits, and track consumption.

AI & Sales AutomationUpdated September 30, 2026

In short

An API key is a secret token that identifies your app to an API, so treat it like a password.

Key points

  1. API keys identify the calling project or account; they are simpler than OAuth but do not represent a specific user's consent [1][2].
  2. Keys are usually sent in a request header, often as a bearer token in the style of RFC 6750, rather than in the URL [3].
  3. OWASP advises keeping secrets out of source code, storing them in a secrets manager and rotating them regularly [4].
  4. Scope each key to the minimum permissions needed and restrict it by IP address or service where the provider allows it [1].
  5. Providers tie Rate Limiting and billing to keys, which matters under Usage-Based Pricing.

What an API key does

When a program calls a REST API, the provider needs to know who is calling. An API key answers that question. It is a long random string issued by the provider and sent with each request, usually in a header. The provider looks it up, checks what it is allowed to do, counts the request against the account's limits and records usage for billing [2]. Google Cloud's documentation notes that API keys identify a project rather than a user, which makes them suitable for server-to-server calls and simple integrations [1]. When an app needs to act on behalf of a particular person, such as reading their mailbox, OAuth is the better choice, because it captures that person's consent and can be limited and revoked separately.

Keeping keys safe

Anyone who has an API key can usually do whatever the key allows, so it should be handled like a password. The OWASP Secrets Management Cheat Sheet recommends storing secrets in a dedicated secrets manager or environment configuration, never committing them to source control, limiting who can read them, and rotating them on a schedule and after any suspected leak [4]. Send keys in headers over HTTPS; the bearer token scheme in RFC 6750 warns against putting tokens in URLs, where they end up in logs and browser history [3]. Issue separate keys for separate integrations, so one can be revoked without breaking the others. Where the provider supports it, restrict keys to specific IP addresses, services or read-only access [1].

API keys in sales stacks

Sales teams often hold many keys at once: one for the CRM (Customer Relationship Management), one or more for enrichment services (several, if a Waterfall Enrichment setup is used), one for an outreach tool, and more for each Workflow Automation connection. Each is a way into systems that hold Personal Data about prospects and customers, so a leaked key can become a data breach under GDPR. Keep an inventory of which keys exist, what each one can access, and who owns it. Remove keys when an integration is retired or a team member leaves. Watch usage: an unexpected spike can mean a leak or a runaway script, and because providers apply Rate Limiting and charges per key, it may also run up costs under Usage-Based Pricing. Signing secrets for webhooks need the same care.

Sources
  1. Manage API keys — Google Cloud Documentation
  2. What Is an API Key? — IBM
  3. RFC 6750: The OAuth 2.0 Authorization Framework: Bearer Token Usage — IETF
  4. Secrets Management Cheat Sheet — OWASP Cheat Sheet Series
External sources open in a new tab.

Related terms

Mentioned in

Outreach without the busywork.

PineLead finds new B2B prospects every day, qualifies them against your criteria and writes the first email in your voice. You approve — PineLead sends.

Start free with 100 credits →