API Keys Overview

Understand what API keys are, how DevSpace APIs work, and how to use them safely.

API Keys

DevSpace APIs allow applications to communicate with backend services using HTTP requests.
To access these APIs, every request must be authenticated using an API key.

API keys help DevSpace:

  • Identify who is making a request
  • Control access to APIs
  • Protect services from misuse

What Is an API Key?

An API key is a unique secret value assigned to your application.

It works like a password that:

  • Identifies your app
  • Grants access to specific APIs
  • Tracks usage and limits

Every request to a DevSpace API must include this key.


How API Keys Work

The general request flow is simple:

  • You generate an API key
  • Your application sends the key with each request
  • The server checks the key
  • Access is allowed or denied based on validity

If the key is missing or incorrect, the request fails.


import express from "express"
const app = express()
app.get("/api/pets", (req, res) => {
  if (!req.headers.authorization) return res.status(401).json({ error: "API key missing" })
  res.json({ pets: [{ id: 1, name: "Dog" }, { id: 2, name: "Cat" }] })
})
app.listen(3000)

Where API Keys Are Used

The same API key concept applies everywhere:

  • Frontend applications
  • Backend servers
  • Mobile apps
  • Third-party services

Once you understand API keys, you can work with almost any API.


Backend Usage Concept

On backend systems, API keys are typically:

  • Sent in request headers
  • Read by the server
  • Validated before processing the request

This pattern is used across most real-world backend projects.


Security Basics

Good security habits are important, even for learning projects.

Do

  • Keep API keys private
  • Store keys in environment variables
  • Regenerate keys if exposed

Don’t

  • Share keys publicly
  • Commit keys to repositories
  • Expose keys in client-side code

Why API Keys Matter

API keys allow DevSpace to:

  • Protect infrastructure
  • Prevent abuse
  • Monitor usage
  • Provide stable learning APIs

Without API keys, APIs would be open and unsafe.


Available Practice APIs

DevSpace provides multiple APIs for hands-on learning.

API NamePurpose
Pet APILearn CRUD operations and REST basics
Books APIPractice pagination and filtering
Product APIWork with real-world e-commerce data

What to Learn Next

After understanding API keys, you can explore:

  • Making authenticated requests
  • Understanding API responses
  • Working with each API in detail

Start with the Pet API to build a strong foundation.