Protect an API credential

Treat your API key like a production secret, because it is one.

Updated September 14, 2026 · 1 min read

  • Never hardcode it. Set it as an environment variable (e.g. PTERI_API_KEY) rather than pasting it into source — see creating your first API key.
  • Never commit it to version control, including in config files, notebooks, or commit history you think you've since removed — a rotation is cheaper than trying to fully scrub git history.
  • Never paste it into a support ticket, chat message, or log statement. If you need to show us a request, redact the key first — see safe diagnostic information without sharing secrets.
  • Scope access so only the services that need the key can read it — e.g. via your platform's secrets manager rather than a shared config file.
  • Rotate on a schedule, not just when something goes wrong — see rotating an API credential.

If you believe a key has already been exposed, don't wait for the next scheduled rotation — see responding to a suspected compromised account and revoking an API credential now.

Still stuck?

Ask Kai about this article, or open a ticket with our team.

Submit a ticket