Skip to content
AI Dev Toolkit.
Esc
  • AI Token CounterCount tokens for GPT, Claude, Gemini, DeepSeek, Qwen and more.Tool
  • LLM API Cost CalculatorEstimate per-request, daily and monthly API costs.Tool
  • AI Model ComparisonCompare prices, context windows and features across models.Tool
  • AI Model Pricing PagesSpecs, real costs and cheaper alternatives for popular models.Tool
  • Context Window CheckerSee whether your text fits each model’s context window.Tool
  • Subscription vs API CalculatorFind out whether a chat plan or the API is cheaper for you.Tool
  • GPU / VRAM CalculatorCheck how much VRAM a local model needs and which GPUs fit.Tool
  • Prompt Caching CalculatorEstimate savings from prompt caching.Tool

AI glossary · Tokens and cost

What is an API key for AI models?

Also called: secret key, API token

Definition

An API key is a secret string that identifies your account to a service such as the OpenAI, Claude or Gemini API, so every request made with it is authorised, rate-limited and billed to you.

Explained

How it works

You create a key in the provider’s console and send it with every request, in an HTTP header. Whoever holds the key can spend your credit, so treat it like a password: it works until you revoke it, unless the console lets you set an expiry.

Providers disagree on the header. OpenAI uses Authorization: Bearer. Anthropic’s API overview now lists Authorization: Bearer first and calls the older x-api-key header a legacy fallback that still works; it also needs an anthropic-version header. Google’s Gemini API uses x-goog-api-key.

Keys belong on a server, in an environment variable or a secret manager. OpenAI and Google both warn against putting them in code that runs in browsers or apps, because anyone can read them there. The exception is BYOK, where you paste your own key into a tool you trust.

Example

Checking a key on three APIs

Each request below lists the provider’s models. It needs a valid key but generates no tokens, so it costs nothing; these are the requests our API key checker sends from your browser. An error reply means the key is wrong, revoked or belongs to another provider.

Key formats help spot a mix-up before you send anything, and the API keys hub shows where to get each one and which are free to use.

How three providers expect the key
ProviderKey starts withHeaderUsual env variable
OpenAIsk-Authorization: BearerOPENAI_API_KEY
Anthropic (Claude)sk-ant-x-api-key or Authorization: BearerANTHROPIC_API_KEY
Google GeminiAQ. (new keys) or AIza (older)x-goog-api-keyGEMINI_API_KEY

Headers from each provider’s API reference, checked 2026-10-11. Prefixes from our API keys comparison.

List models with each key (free, no tokens used)
curl https://api.openai.com/v1/models \
  -H "Authorization: Bearer $OPENAI_API_KEY"

curl https://api.anthropic.com/v1/models \
  -H "x-api-key: $ANTHROPIC_API_KEY" \
  -H "anthropic-version: 2023-06-01"

curl https://generativelanguage.googleapis.com/v1beta/models \
  -H "x-goog-api-key: $GEMINI_API_KEY"

Cost and quality

Why it matters

A leaked key is a bill: anyone who has it can run requests on your account until you revoke it. Use one key per app or environment so you can revoke one without breaking the rest, set spending limits where the provider offers them, and never commit keys to a repository.

The key also decides which rate limits and billing apply. A tool that quietly picks up an old key from an environment variable can bill the wrong account or hit low limits.

Don’t mix up

Common confusions

API key vs access token
An API key is long-lived and created by you in a console. An access token is short-lived and issued after a sign-in or token exchange. Some APIs accept both in the Authorization header, but they are managed differently.
API key vs subscription login
Signing in to Claude Code with a subscription is not an API key. If an ANTHROPIC_API_KEY is set in your environment, Claude Code can use it instead, with that key’s billing and limits.

Go deeper

Try it and read more

Related

All 40 terms in the AI glossary