AI glossary · Tokens and cost
What is an API key for AI models?
Also called: secret key, API token
Definition
An API key is a secret string that identifies your account to a service such as the OpenAI, Claude or Gemini API, so every request made with it is authorised, rate-limited and billed to you.
Explained
How it works
You create a key in the provider’s console and send it with every request, in an HTTP header. Whoever holds the key can spend your credit, so treat it like a password: it works until you revoke it, unless the console lets you set an expiry.
Providers disagree on the header. OpenAI uses Authorization: Bearer. Anthropic’s API overview now lists Authorization: Bearer first and calls the older x-api-key header a legacy fallback that still works; it also needs an anthropic-version header. Google’s Gemini API uses x-goog-api-key.
Keys belong on a server, in an environment variable or a secret manager. OpenAI and Google both warn against putting them in code that runs in browsers or apps, because anyone can read them there. The exception is BYOK, where you paste your own key into a tool you trust.
Example
Checking a key on three APIs
Each request below lists the provider’s models. It needs a valid key but generates no tokens, so it costs nothing; these are the requests our API key checker sends from your browser. An error reply means the key is wrong, revoked or belongs to another provider.
Key formats help spot a mix-up before you send anything, and the API keys hub shows where to get each one and which are free to use.
| Provider | Key starts with | Header | Usual env variable |
|---|---|---|---|
| OpenAI | sk- | Authorization: Bearer | OPENAI_API_KEY |
| Anthropic (Claude) | sk-ant- | x-api-key or Authorization: Bearer | ANTHROPIC_API_KEY |
| Google Gemini | AQ. (new keys) or AIza (older) | x-goog-api-key | GEMINI_API_KEY |
Headers from each provider’s API reference, checked 2026-10-11. Prefixes from our API keys comparison.
curl https://api.openai.com/v1/models \
-H "Authorization: Bearer $OPENAI_API_KEY"
curl https://api.anthropic.com/v1/models \
-H "x-api-key: $ANTHROPIC_API_KEY" \
-H "anthropic-version: 2023-06-01"
curl https://generativelanguage.googleapis.com/v1beta/models \
-H "x-goog-api-key: $GEMINI_API_KEY"Cost and quality
Why it matters
A leaked key is a bill: anyone who has it can run requests on your account until you revoke it. Use one key per app or environment so you can revoke one without breaking the rest, set spending limits where the provider offers them, and never commit keys to a repository.
The key also decides which rate limits and billing apply. A tool that quietly picks up an old key from an environment variable can bill the wrong account or hit low limits.
Don’t mix up
Common confusions
- API key vs access token
- An API key is long-lived and created by you in a console. An access token is short-lived and issued after a sign-in or token exchange. Some APIs accept both in the
Authorizationheader, but they are managed differently. - API key vs subscription login
- Signing in to Claude Code with a subscription is not an API key. If an
ANTHROPIC_API_KEYis set in your environment, Claude Code can use it instead, with that key’s billing and limits.
Go deeper
Try it and read more
Related
Related terms
- BYOKBYOK (bring your own key) is a model where an AI app or tool runs on your own API key from a provider such as OpenAI, Anthropic or Google, so usage is billed to your account instead of the app’s.
- Rate limitA rate limit is a cap on how many requests or tokens an account may send to an API per minute or per day, and going over it makes the API reject requests with HTTP 429 until the allowance refills.
- OpenAI-compatible APIAn OpenAI-compatible API is a model API that accepts OpenAI’s Chat Completions request format, so you can call it with the official OpenAI SDK by changing only the base URL, the API key and the model name.