Protect an API credential
Treat your API key like a production secret, because it is one.
- Never hardcode it. Set it as an environment variable (e.g.
PTERI_API_KEY) rather than pasting it into source — see creating your first API key. - Never commit it to version control, including in config files, notebooks, or commit history you think you've since removed — a rotation is cheaper than trying to fully scrub git history.
- Never paste it into a support ticket, chat message, or log statement. If you need to show us a request, redact the key first — see safe diagnostic information without sharing secrets.
- Scope access so only the services that need the key can read it — e.g. via your platform's secrets manager rather than a shared config file.
- Rotate on a schedule, not just when something goes wrong — see rotating an API credential.
If you believe a key has already been exposed, don't wait for the next scheduled rotation — see responding to a suspected compromised account and revoking an API credential now.