An API key is a long random string the client sends (usually in a header) to identify itself. Simple to issue and use, good for server-to-server and rate-limiting per client. But a key is a static secret: it identifies an app, not a user, doesn't expire on its own, and is dangerous if leaked. Never embed keys in client-side code.