{
  "id": 891262,
  "title": "Secure your API keys and other application keys",
  "url": "https://urgent.news/2026/08/14/api-key",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-14T17:22:45.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/yo1995/bao-hu-api-key-he-qi-ta-ying-yong-mi-yao-45hp"
  },
  "original_language": "zh",
  "account": "API keys and other application keys are crucial for securing applications that use various map services. These keys have costs based on usage, and the more users an app has, the higher the costs. While it is desirable to attract more users, securing API keys is essential to prevent hackers from stealing them and using them for their own benefit. Hard-coding API keys in an app is not recommended due to two main reasons: hackers may extract keys from binary files, and API keys may need to be updated periodically, requiring a new app version. Setting a one-year expiration period for keys can allow hackers to use them for nearly a year without incurring costs. When API keys expire, apps cannot function, forcing developers to release new versions and update all users.\n\nOne approach to address these issues is to avoid hard-coding API keys in an app. Instead, developers can retrieve keys dynamically from a server using OAuth 2.0 Application Credentials. These credentials consist of a Client ID and Client Secret, and they allow developers to generate short-term, usage-based tokens dynamically. By using servers to host these credentials, developers can prevent token interception and MitM attacks, as the tokens are not transmitted through the network. This method eliminates the risk of API keys being stolen and used for unauthorized access, making it a more secure solution for securing APIs.",
  "summary": "Let's try to translate the experience document about API Key we summarized... Scenario: Assume we are about to release an app based on ArcGIS Maps SDK and use API Key to authorize various map services. The cost of API Key depends on the usage of interface calls. The more normal users, the greater the usage, and the higher the cost. No problem - we certainly hope to have more users. However, assume a hacker decides to steal our key, if he can exploit a vulnerability to obtain the API Key, his usage will ultimately be counted on our bill. We should not directly hard-code the key into the app, mainly for two reasons: The API Key may be extracted by hackers from binary files. When the API Key needs to be replaced, there is no need to reissue a new version. The API Key will expire, but generally, the validity period is longer. If we set the key to expire in one year when creating it, the hacker can use it for almost a year for free. API Key...",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}