API key, explained
An API, or application programming interface, lets one piece of software talk to another. An API key is how the receiving side knows who is calling. It is a long random string, issued by the service, that the calling program includes with each request, usually in a header. The service checks the key, identifies the account and system it belongs to, and allows only what that key is permitted to do.
An API key works like a password for a program rather than a person, and it deserves the same care. Give every integration its own key, so a key leaked by one website form can be revoked without breaking your other systems. Grant each key only the access it needs; a key that only sends in leads should not be able to read your customer list. Store keys in a server's environment settings or a secrets manager, never in website code that visitors can see, in a shared document or in a chat message.
Rotate keys from time to time and whenever someone who had access leaves, and watch the audit log for use you do not recognise. For example, a Hyderabad real estate firm connecting its property website to its CRM should create a key just for that website, kept on its server. DigiPix Flow gives each system its own key, shown once, stored as a hash and recorded in your audit log.