02·Hands-on·8 min

API keys

An API key tells the DontCode gateway "this request comes from my project's server." Anyone holding it can act as your server, so it belongs in server environment variables only.

DontCode stores only a hash of each key. You see the full key once, at creation; after that only the last four characters are shown. Lost a key? Revoke it and make a new one. Revoking is instant.

Check your understanding

  1. 1.Where should your project API key be used?

Your task

Backend Project

Open Keys in your Backend Project and create a new API key.