An API key is a secret value that identifies and authenticates your backend when it calls an AI provider.

Why is it needed?

AI APIs are paid and protected services. The provider needs to know:

A request commonly includes the key in an authorization header:

Authorization: Bearer YOUR_API_KEY

Correct request flow

flowchart LR
    A["Frontend"] --> B["Your backend"]
    B --> C["AI API"]
    C --> B
    B --> A

The API key stays on your backend.

The frontend calls your backend, and your backend calls the AI provider.

Never expose the key in frontend code

This is unsafe:

// Browser code — do not do this
const API_KEY = "secret-key";

Anyone can inspect the browser, copy the key, and use your account.

Store the key in an environment variable:

AI_API_KEY=your-secret-key

Use it on the server:

const client = new AIClient({
  apiKey: process.env.AI_API_KEY
});

Do not commit the environment file to Git.

Authentication vs authorization

The provider authenticates your backend with the API key. Your backend must separately authenticate its own users and decide who can use its AI features.

Important security practices

Your backend still needs user-level protection

One server key may be shared by all users of your application.

Therefore, your backend should track:

The AI provider's API key protects the provider account. It does not replace authentication, authorization, or rate limiting inside your own application.

If a key is leaked

  1. Revoke or rotate it immediately.
  2. Create a replacement key.
  3. Update the production secret.
  4. Review usage and billing.
  5. Find and remove the source of the leak.

Final mental model

Frontend → your authenticated backend → AI provider.

The provider key never belongs in the browser.