← Glossary
Concept

API Key

A static secret string used to authenticate an application or caller to an API. Simple but weak: it does not expire on its own, is easy to leak, and should be vaulted and rotated.