I have an application I'm developing that's pure javascript and consumes the Stack API. My API key is embedded in the source which anyone could read. Is this safe?
1 Answer
Yes.
Your API key identifies your application for stat tracking purposes more-so than security purposes. It is safe to leave in a plain text, user readable, format.
3 Comments
Soviut
that's what I figured, since it's being passed around in querystring and headers. Thanks for confirming.
Kevin Montrose
@Soviut - no problem. I've realized that maybe we shouldn't have called it a "key" (in v1, anyway) but we're stuck with the terminology now. Maybe "app id" would have been better...
Thomas
@Kevin Montrose I have seen a trend toward "app id" as the new lingo.