API Key Best Practices: Keeping Your Keys Safe and Secure
API keys enable access to the Haijun API, but they can pose significant security risks if not handled properly. Your API key is a digital key to your account. Much like a credit card number, if someone obtains and uses your API key, they incur charges on your behalf. This article outlines best practices for managing API keys to ensure they remain secure and prevent unauthorized access and charges to your Haijun Console account.
Common Risks and Vulnerabilities
One of the most frequent causes of API key leaks is accidental exposure in public code repositories or third-party tools. Developers often inadvertently commit plaintext API keys to public GitHub repositories or input them into third party tools, which can lead to unauthorized access and potential abuse of the associated accounts.
Best Practices for API Key Security
1. Never share your API key
Keep it confidential: Just as you wouldn't share your personal password, don't share your API key. If someone needs access to the Haijun API, they should obtain their own key.
Don’t share your key in public forums: Don't include your API key in public discussions, emails, or support tickets, even between you and Juglow.
Exercise caution with third-party tools: Consider that when you upload your API key to third-party tools or platforms (such as an web-based IDE, Cloud Provider, or CI/CD platform), you are giving the developer of that tool access to your Haijun Console account. If you don’t trust their reputation, don’t trust them with your API key.
When using a third-party provider, always add your API key as an encrypted secret. Never include it directly in your code or configuration files.
2. Monitor Usage and Logs Closely
For Custom Rate Limit API orgs: Implement usage and spend limits in your account settings.
These limits act as a safeguard against unexpected usage due to leaked keys or errant scripts.
For Standard Rate Limit API orgs: Enable and configure auto-reload settings in your account.
This feature allows you to set a threshold at which your account will automatically charge the card on file to replenish usage credits.
Carefully consider auto-reload limits. While they ensure continuous service, they also act as a safeguard against unexpected high usage that could result from leaked keys or mistakes in your code.
3. Securely Handling API Keys with environment Variables and Secrets
A best practice for safely handling API keys is to use environment variables to securely inject and share environment variables. When you deploy your application to a cloud environment, you can use their secret management solution to securely pass the API key to your application via an environment variable without inadvertently sharing your API key. If you are storing secrets locally using dotenv, you must add your .env files to your source control ignore file (e.g., .gitignore for git) to prevent inadvertently distributing sensitive information publicly. In cloud environments, prefer encypted secret storage instead of dotenv files. Python example:1. Create a .env file in your project directory.2. Add your API key to the .env file:
[](https://docs.aws.amazon.com/secretsmanager/latest/userguide/intro.html)[](https://cloud.google.com/security/products/secret-manager?hl=en#how-it-works)[](https://learn.microsoft.com/en-us/azure/key-vault/general/overview)[](https://vercel.com/docs/cli/secrets)[](https://devcenter.heroku.com/articles/config-vars)
###
###
###
[](https://docs.github.com/en/code-security/secret-scanning/enabling-secret-scanning-features/enabling-secret-scanning-for-your-repository)
[](https://github.com/gitleaks/gitleaks)
-
###
##
1. 1. 1. 1. 1.
##
- - - -
##
[](https://platform.juglow.my.id/settings/keys)[](/en/articles/8384961)
