Managing API Keys Securely
What this article covers
- Why API keys deserve special protection.
- How to generate and store keys safely.
- How to rotate and revoke keys.
- Which tools work well for local secrets management.
- Common mistakes and best practices.
Introduction: Managing API keys securely
API keys are like passwords for software. They grant access to models, cloud services, databases, and other interfaces. Exposing them risks data loss, unauthorized charges, or unwanted access. In local AI setups, you often need keys for external models, webhooks, or internal APIs. Even when self-hosting, secrets like API keys and tokens must be protected.
Secure management involves more than just a long password. It encompasses generation, storage, distribution, rotation, and monitoring. Doing this systematically cuts your risk significantly.
Why do I need secure API keys?
Key reasons:
- Protection against misuse: A stolen key can rack up charges.
- Data privacy: Keys may access sensitive information.
- Access control: Who gets to use which API?
- Audit trails: Who used which key and when?
- Emergency response: Keys must be revocable quickly.
API keys explained
An API key is a secret that an application presents to a service to prove authorization. Usually it’s sent in the request header.
Important terms:
- API Key: A static key, often valid long-term.
- Token: A time-limited secret.
- Secret: Any sensitive configuration data.
- Scope: The permissions granted by a key.
- Rotation: Renewing keys periodically.
- Revocation: Withdrawing a key’s validity.
Who should manage API keys?
- Self-hosters using external models.
- Developers consuming APIs.
- DevOps teams managing multiple services.
- Teams that need to share credentials.
- Anyone taking security seriously.
Key tools and concepts for secrets management
- HashiCorp Vault: Enterprise secrets manager.
- Bitwarden Secrets Manager: Simple secrets manager.
- Infisical: Open-source alternative.
- Doppler: Cloud-based secrets manager.
- .env file: Local environment variables file.
- dotenvx: Encrypted .env files.
Secure generation
- Length: At least 32 random characters.
- Randomness: Use a cryptographically secure generator.
- Unpredictability: Don’t build keys from dictionary words.
- Prefixes: Use prefixes like
sk_live_orsk_test_. - Separation: Keep production and development keys separate.
Secure storage
- Never in code: Don’t commit keys to repositories.
- Never in logs: Disable logging or redact sensitive output.
- Environment variables: Only in secure storage.
- Secrets manager: For distributed teams.
- File permissions: .env files readable only by the process.
- Backups: Encrypt secrets before backing them up.
Distribution and access
- Per environment: Use separate keys for development, staging, production.
- Least privilege: Grant keys only the permissions they need.
- Usage limits: Set caps per key.
- Audit logging: Record every use.
- Automated rotation: Renew on a schedule.
Rotation and revocation
- Regular schedule: Change keys periodically or on suspicion of compromise.
- Immediate action: Revoke at once if a leak is suspected.
- Overlap period: Allow time for the new key to take effect.
- Notify the team: Let people know when keys change.
- Test first: Verify new keys work before retiring the old ones.
Local tools for secrets
- .env with
source: Quick, but unencrypted. - Docker Secrets: For containerized environments.
- systemd credential: For Linux systems.
- pass or KeePassXC: Password managers for small teams.
- 1Password Secrets: For distributed teams.
Common pitfalls
- Keys in Git: Once pushed, the key must be rotated immediately.
- No expiration: Keys live forever and get forgotten.
- Overprivileged keys: A single key grants too many permissions.
- No monitoring: Abuse goes undetected.
- Hardcoded values: Hidden in source code.
- No rotation: Old keys stay active.
Further reading and resources
FAQ: API Keys
Are API keys the same as passwords? Similar, but usually longer and designed for programs rather than humans.
Can I store API keys in .env files? Yes, but only locally and with proper file permissions. For teams, a secrets manager is better.
How often should I rotate? At least annually, immediately if you suspect a breach.
What’s the difference between an API key and a token? API keys are often long-lived; tokens typically have an expiration date.
Which secrets manager for local AI? Bitwarden Secrets, Infisical, or dotenvx work well for small setups.
Sources and further reading
- NIST SP 800-57: Key Management: https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final
- OWASP Secrets Management: https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
- Infisical: https://infisical.com/
Summary: Managing API keys securely
API keys are sensitive secrets that demand protection. Secure generation, isolated storage, least-privilege access, regular rotation, and monitoring dramatically reduce your risk. For local AI, .env files, Docker Secrets, or specialized secrets managers all work. Treat keys like passwords, and you’ll avoid most common security gaps.


