freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #32 of 45

api keys · the simplest secret

RestaVSThe 401 Bandit
Resta saysAPI keys are the simplest credential — a secret string identifying the caller.

An API key is a long random string the client sends (usually in a header) to identify itself. Simple to issue and use, good for server-to-server and rate-limiting per client. But a key is a static secret: it identifies an app, not a user, doesn't expire on its own, and is dangerous if leaked. Never embed keys in client-side code.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleExplain why an API key belongs on a server, not in browser JavaScript.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>X-API-Key: sk_live_8f3a...   (server → server)
in browser JS → anyone can read it in DevTools</pre></body></html>
▶ Open the interactive comic issue
‹ Authorization · What Can You DoBasic Auth · The Legacy Header ›