API Key
An API key is a secret string that identifies the app or person calling an API. It is sent with every request so the service knows who is asking.
A long-lived secret that authenticates your code to an API, such as a social media publishing API.
Key Points
- ✓An API key identifies the calling app or account and is sent with every request, usually in an HTTP header
- ✓API keys are usually long-lived, while OAuth access tokens expire and carry user consent
- ✓Keep keys on the server, out of Git and browser code, and rotate them if they leak
An API key is a secret string that identifies the app or person calling an API. You send it with every request, and the service uses it to decide who you are and what you may do. 1
How API keys work
You create a key in the service’s dashboard and store it somewhere safe. Your code then adds it to each request, usually as an HTTP header. The service looks the key up, checks its permissions and either runs the request or rejects it.
API key vs. OAuth access token
- API key: created by you, usually long-lived, identifies your app or account.
- Access token: issued through OAuth after a user agrees, limited to specific permissions and set to expire. 2
Many platforms use both. A publishing tool might give you one API key for its own API, while it holds OAuth tokens for each connected social account behind the scenes.
Keeping an API key safe
- Keep it on the server. Never put it in browser or mobile app code, where anyone can read it.
- Store it in environment variables or a secrets manager, not in Git.
- Delete keys you no longer use, and create a new one if a key may have leaked.
API keys in Publora
The Publora API uses an API key sent in the x-publora-key header. You create it in the dashboard under API. The full key is shown only once, so copy it right away. Publora keys do not expire and need no refresh flow. 3
Your social accounts are connected separately, once, through each network’s OAuth screen in the Publora dashboard. Your code only ever handles the Publora key, never the LinkedIn or Instagram tokens.
Publora and API Key
The Publora API and MCP server publish and schedule posts to 10 networks from your own code or from AI assistants like Claude, ChatGPT and Cursor.
See the Publora API →Related Terms
- API
An API (Application Programming Interface) is a set of rules that enables software applications to communicate and exchange data, allowing social media platforms to integrate with third-party marketing tools.
- API Rate Limit
An API rate limit caps how many requests a client can make in a set period. Requests over the limit are rejected, usually with HTTP 429 Too Many Requests.
- Access Token
An access token is a credential an app sends with API requests to act on your behalf. It is issued through OAuth, limited to specific permissions and set to expire.
- OAuth
OAuth is an open standard that lets you give an app limited access to your account on another service without sharing your password.
- Publishing API
A programmatic interface that enables automated creation, uploading, and scheduling of content across social media platforms without manual intervention.
- Webhook
Automated HTTP callbacks that send real-time data between applications when specific events occur, enabling instant integration without constant polling.