Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Keep AI API keys on trusted servers, limit what each key can access, and revoke a key as soon as you suspect it has leaked. For production, store credentials in a controlled secrets system rather than in code or a deployed app. A key can authorize requests, but it is not a complete security boundary: protect sensitive services with separate authorization, usage controls, and monitoring.
What an API key protects—and what it does not
An API key is a credential: whoever can use it may be able to make requests as the associated account, project, or workload, subject to the provider’s controls. Depending on the service, keys can also help track usage or enforce an API plan. They do not, by themselves, establish that a request is authorized to access a particular user’s sensitive data or perform a high-impact action.
OWASP cautions against relying exclusively on API keys to protect sensitive, critical, or high-value resources. Add authorization checks appropriate to the application, and use network restrictions, rate controls, and monitoring where available. Treat a key as one layer of defense, not as a substitute for the rest of the design. OWASP REST Security Cheat Sheet
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsWhere to store an API key
Local development
For a personal development setup, an environment variable can keep a key out of source code. OpenAI recommends this as a proactive measure, but an environment variable is not a vault: it may still be exposed through a developer’s machine, process access, shell history, logs, or configuration mishandling. Keep local configuration out of version control and restrict access to the machine and account that use it. OpenAI API key safety guidance
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
CI/CD workflows
Use the CI/CD platform’s protected secrets mechanism for credentials a build or deployment needs. Give each job only the access it requires, avoid printing secrets in logs, and check whether pull requests from untrusted contributors can run workflows that expose secrets. Where a platform offers a short-lived workload identity or equivalent federation, prefer it to a long-lived key when supported and practical.
For GitHub Actions, GitHub recommends the built-in GITHUB_TOKEN for workflow tasks. For personal use, it recommends personal access tokens; for actions on behalf of an organization or another user, it recommends GitHub Apps. Choose the authentication method for the task and limit its permissions. GitHub credential guidance
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Production applications
Keep production credentials in a controlled server-side mechanism or secrets-management service, and have the application retrieve them through an appropriately restricted identity. Do not embed a key in a browser or mobile app, bundle it into client code, or include it in a build artifact: users can inspect those files and extract the credential. OpenAI’s guidance is explicit: “Never deploy your key in client-side environments like browsers or mobile apps.” Route client requests through a backend that can authenticate users and apply the application’s own authorization rules. OpenAI API key safety guidance OWASP Key Management Cheat Sheet
A private repository is still not a safe place for an unencrypted key. Repository access can expand, credentials can persist in history, and automated systems may copy them into logs or artifacts. GitHub advises against committing plaintext credentials even to private repositories. GitHub credential guidance
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Choosing a storage approach
There is no universally best secret store. Start with a provider-native or platform-native option if it meets your threat model and the team can operate it reliably. Consider a dedicated secrets-management service when central policy, multiple platforms, stronger auditing, access control, or rotation justify the extra system and administrative work.
| Approach | Best fit | Key trade-off to assess |
|---|---|---|
| Local environment variable or ignored local config | Individual development and testing | Easy to adopt, but does not provide centralized production access control or lifecycle management. |
| CI/CD platform secrets | Build and deployment jobs that need credentials | Review which users and workflows can access secrets, including untrusted contribution paths and logs. |
| Cloud-provider secret store or vault | Applications running in a provider’s environment | Can integrate with workload identity and provider controls; verify access boundaries, audit, recovery, and portability needs. |
| Dedicated secrets-management system | Teams needing centralized policy across services or platforms | Can add lifecycle and audit controls, but also operational complexity, availability dependencies, and administrative overhead. |
Before choosing, check who or what can read or use the secret; whether production and development credentials can be separated; how expiration, rotation, and emergency revocation work; whether accesses and changes are auditable; and how dependent applications behave during an outage. For a managed store, also plan encrypted backups, tested restoration, and a break-glass process. OWASP emphasizes both lifecycle controls and availability: a secret store must be protected, but its failure should not leave the service without a recovery path. OWASP Secrets Management Cheat Sheet
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Limit each key’s access and exposure
- Use a separate key or identity for each person, service, environment, or purpose when the provider supports it. This makes access easier to limit and a single compromise less likely to affect unrelated systems.
- Grant only the permissions the specific user or workload needs. Avoid using an account-wide or broadly privileged credential for a narrow task.
- Keep development and production secrets separate. Do not let a test job or developer credential inherit production access without a clear need.
- Use expiration or short-lived credentials where supported. OpenAI recommends workload identity federation for supported workloads as an alternative to long-lived API keys.
- Apply network restrictions, usage monitoring, and spend controls where available. Treat spending limits as guardrails, not guaranteed hard ceilings: OpenAI notes that limits may not block traffic immediately and can be exceeded slightly.
For teams, a secure shared credential system may be appropriate for sharing secrets among people. That does not make a consumer password manager equivalent to a production secrets manager, which also needs suitable workload access, lifecycle, and operational controls. GitHub credential guidance OpenAI API key safety guidance
Recommended Free Tools
Rotate and revoke keys deliberately
Set an expiration or rotation process if the provider supports it, but do not assume one schedule fits every key. The right cadence depends on the key’s permissions, purpose, exposure, and operational context. A rotation process should identify the owner and dependent systems, issue a replacement, update consumers, confirm the new credential works, and then retire the old one. OWASP Key Management Cheat Sheet
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Revoke a key promptly if you suspect exposure; do not wait for proof of misuse. Replace it in every system that depends on it, then inspect usage and billing for activity you do not recognize. Check likely copies in source history, CI logs, build artifacts, client bundles, and deployment outputs. Secret scanning can help find or prevent some supported credentials from being committed, but it does not invalidate a leaked key. GitHub’s remediation guidance is to generate a replacement, update its uses, and delete the compromised credential. GitHub credential guidance OpenAI API key safety guidance
Quick Recap
A practical setup by stage
For a solo developer
- Create a key with the narrowest permissions the provider offers for the task.
- Keep it in local configuration excluded from version control; use an environment variable if that fits the development setup.
- Do not paste it into browser code, mobile code, a repository, a command line that may be recorded, or a log.
- Monitor provider usage and revoke the key if it appears anywhere it should not.
For a small production team
- Create distinct credentials for development, staging, production, and separate workloads where supported.
- Store production secrets in a controlled secret store and grant applications access through restricted workload identities.
- Limit CI/CD access to the specific jobs and deployment environments that need a credential; prefer federation or short-lived access where available.
- Assign an owner, document dependent systems, and define how to rotate, revoke, audit, and recover the credential.
- Monitor requests and spend, and add application-level authorization and rate protections for sensitive or costly operations.
Common mistakes to avoid
- Putting a key in frontend code: obfuscation does not make a shipped credential secret. Keep provider credentials on a backend.
- Trusting a private repository: repository privacy does not prevent leaks through history, collaborators, automation, or copied artifacts.
- Using one key everywhere: shared credentials make it harder to isolate access, identify a source of misuse, and revoke without disruption.
- Treating secret scanning as remediation: detection does not revoke a credential already exposed.
- Assuming an API key is authorization: authenticate and authorize users in the application, especially before granting access to sensitive data or high-impact actions.
- Relying on a spending limit as an instant shutoff: provider controls may have delay or slight overshoot, so monitor usage and apply additional limits where needed.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

