An API key is a long string of letters and digits that a service issues to a user or developer. By itself it means nothing, but it serves as a "passport" for programs: when an application contacts a service and passes the key, the service understands exactly who is requesting data and whether they have the right to do so.
What an API is and where the key comes in
An API is a set of rules that lets one program communicate with another. For example, a player statistics website requests match data from a platform, and a trading bot checks item prices. To keep just anyone from getting at the data, the service asks for a key to be presented. The key is tied to a specific account, so the service treats all actions performed with it as actions of the account owner.
Where players encounter this
In the esports scene, API keys come up in several situations:
- statistics websites and apps that pull a player's data from external sources;
- Discord and streaming bots that display ratings or match results;
- services that work with in-game items and trading marketplaces;
- tournament platforms and organizer tools where a key is needed for automation.
Usually the key is created in the account settings on the platform's official website: the player gets it themselves, copies it, and pastes it into the program they need.
Why you must not share a key with strangers
The main rule is simple: an API key is not just a string, it is access to the capabilities of your account. What exactly someone who obtains the key can do depends on the platform and on which permissions the key was granted. In the worst case, a key can be used to perform actions on your behalf, for example managing items or sending requests you never approved.
That is why experienced players follow a few rules:
- do not send the key in chats, private messages, or on public forums;
- do not publish it in plain view: not in screenshots, not in videos, not in code posted online;
- enter the key only on sites and in programs you have reason to trust;
- if a service asks for a key but does not explain why it needs it, treat that as a red flag;
- at the slightest suspicion that the key has fallen into the wrong hands, delete it immediately in your account settings and create a new one.
A typical situation
A player finds a website that promises a profitable item exchange and asks them to paste in an API key to "connect." A few minutes later it turns out that actions are happening on the account that the owner did not perform. The key, handed over "for convenience," acted as a lockpick. This is a classic scammer scheme: the person hands over access themselves, without understanding what exactly they are giving away.
Key and password: what's the difference
A password is for logging in to the account yourself. A key is for letting a program act on the account's behalf without entering the password. These are different ways of gaining access, but the consequences of a leak are serious in both cases. A good habit is to treat a key as carefully as a password and to revoke it when it is no longer needed.