▶ Stepthrough All tutorials Blog Glossary Prompts Videos Visual guides Start Learning Free

What is an API key?

Updated · By Robert Breen

An API key is a long secret code that lets software use a service's API on your behalf. It proves the request comes from your account, so the service knows whom to allow and whom to bill. Anyone holding the key can use it, which makes it as sensitive as a password.

Why it matters for a small business

For AI automation, the key that matters most is usually your OpenAI key. It's what lets an n8n agent use a model, and because the API charges per request, it's tied to your money. A leaked key can be used by strangers until you revoke it, and you pay for whatever they run.

Keys also explain a confusing first error. A brand-new key on an account with no credit doesn't fail politely; it just returns errors. And keys are usually shown only once, so a business needs a habit for storing them: a password manager or the credential store of the tool that uses them, never a shared doc or a chat thread.

In a real lesson: n8n AI Agent Tutorial: Save Social Media Ideas to Google Sheets

The AI Social Media Idea Agent lesson gets a key before building an agent for BrightPath Marketing, the made-up agency in the lesson. You go to platform.openai.com, the developer side, which the voice-over stresses is billed separately from ChatGPT. First you click Add to credit balance, because a key with a zero balance only returns errors. The lesson suggests ten dollars is plenty to start, since you pay per request.

Then API Keys, + Create new secret key, and a name that says what will use it: n8n agent. You leave Project and Permissions alone, click Create secret key, and get one chance to Copy it. OpenAI never shows it again; if you lose it, you delete it and make another.

Back in n8n, the key goes in exactly one place: the OpenAI Chat Model node's Credential to connect with dropdown, + Create new credential, paste, Save. n8n tests the connection and stores it for every future workflow. The practice key in the lesson is a fake, sk-proj-EXAMPLE-not-a-real-key-0000, so nothing real ever appears on screen.

n8n AI Agent node with a system message written for BrightPath Marketing
n8n AI Agent node with a system message written for BrightPath Marketing

Try this lesson free or read the step-by-step guide.

Common confusions

API key vs password

Both prove who you are, but an API key is meant for software, not people, and you can have several, one per tool. If one leaks, you revoke just that key without touching anything else.

API key vs credential

The key is the secret itself. A credential in n8n is where that secret is stored and attached to nodes. You paste the key once; after that, nodes pick the credential from a list.

API key vs ChatGPT subscription

A ChatGPT plan doesn't include API access. The key draws on a separate, pay-as-you-go balance. See API usage billing.

Tips

  • Name each key after what uses it, so you can revoke the right one without guessing.
  • Never paste a key into a chat, a code file or a screen recording. If it shows up on screen, revoke it.
  • If the provider offers usage limits or alerts in its billing settings, turn them on.

Where you use it: free lessons

Frequently asked questions

What should I do if my API key leaks?
Revoke or delete it in the provider's dashboard right away, create a new one, and update the credential in n8n. Then check your usage for anything you didn't run.
Why does my new OpenAI key give errors?
A common cause is an account with no credit. Add to your credit balance on platform.openai.com, then try again.

All AI glossary terms, A to Z · Free prompt templates