In plain language
It is a machine-facing secret or identifier sent with requests so a provider can apply access rules, quotas, and auditing.
Example
A server includes an API key in an authorization header when calling an enrichment service.
Related terms
API · Oauth · Rate Limit
Common misconception
An API key is not harmless configuration; exposed keys can permit unauthorized use and unexpected charges.
Implementation guidance
Keep keys in a secrets manager, restrict their scope and origin where supported, never commit them, and rotate them after suspected exposure.