How to Get a Claude API Key (and Keep It Safe)
Step by step: create an account on the Claude Developer Platform, add credits, create an API key, set a spend limit, and make your first request. Plus the difference between an API key and a Claude subscription, and where to store the key so it never leaks.
An API key lets your own code use Claude — in an app, a script, or tools that ask for one. Here's how to get one, and the few things to set up before you use it.
API key vs Claude subscription
These are separate:
- A Claude subscription (Free, Pro, Max) is for using Claude yourself — in the Claude apps and in Claude Code.
- An API key is for software calling Claude, billed per token from prepaid credits. (Claude API pricing explained)
A Pro or Max subscription doesn't include API credits, and API credits don't give you a subscription. If you only want to use Claude Code, you usually don't need an API key — logging in with your subscription is simpler and often cheaper. (Claude Pro vs Max vs API key for Claude Code)
Step 1: create a developer account
Go to the Claude Developer Platform at platform.claude.com (the old console.anthropic.com address redirects there) and sign up.
Step 2: add credits
API usage is prepaid. Open Billing, add a payment method, and buy credits. Start small — a few dollars goes a long way while you're testing with a small model.
Step 3: set a spend limit
Before creating a key, set a monthly spend limit in your organisation's limits settings. If the key ever leaks or your code loops by mistake, this caps the damage. Do this now, not later.
Step 4: create the key
Open API Keys, click Create Key, give it a descriptive name ("recipe-app-production"), and copy it. It starts with sk-ant-.
You only see the full key once. Store it immediately (below). If you lose it, delete it and create a new one.
Step 5: store it as an environment variable
Never paste the key into your code. Put it in an environment variable:
# .env (and add .env to .gitignore!)
ANTHROPIC_API_KEY=sk-ant-...
Anthropic's official SDKs read ANTHROPIC_API_KEY automatically. (Environment variables explained, .gitignore explained)
Step 6: make a test request
curl https://api.anthropic.com/v1/messages \
-H "x-api-key: $ANTHROPIC_API_KEY" \
-H "anthropic-version: 2023-06-01" \
-H "content-type: application/json" \
-d '{
"model": "claude-haiku-4-5",
"max_tokens": 200,
"messages": [{"role": "user", "content": "Say hello in five words."}]
}'
If you get a JSON reply with Claude's answer, it works. (What is curl?)
Keeping it safe
- Never put it in frontend code. Anything shipped to the browser — including variables starting with
VITE_orNEXT_PUBLIC_— can be read by anyone. Call Claude from your backend. (Keep API keys out of an AI-built app) - Never commit it to Git. Even in a private repo. (GitHub secret scanning)
- One key per app or environment, so you can revoke one without breaking the rest.
- Don't paste it into chats, screenshots or support tickets.
- Rate-limit your own users, so a single user can't burn through your credits. (Stop bots running up your AI bill)
If it leaks
Delete the key in the console immediately, create a new one, update your app, and check your usage for anything unexpected. (I leaked an API key. What now?)
Using the key with Claude Code
Claude Code can use an API key instead of a subscription — useful in CI or for pay-as-you-go billing. Set ANTHROPIC_API_KEY in the environment and Claude Code will use it. Note that it then bills the API, not your subscription. (Claude Code GitHub Actions)
EasySpawn gives your app a server-side backend with environment variables kept out of your code, so your Claude key stays on the server where it belongs. See how it works or join the waitlist.
Related: What Is an API Key? · Claude API Pricing Explained · How to Build an AI App · OpenAI API vs Claude API
Keep reading
What Is an API Key? A Plain-English Guide (With Claude and ChatGPT Examples)
An API key is a password for software. What API keys are, how they're different from your login, how to get one for Claude or OpenAI, where to keep it, why it must never be in your frontend code, and what to do if one leaks.
Why Does AI Hallucinate? And How to Reduce It in Your App
AI models sometimes state false things with complete confidence. Why it happens — they predict plausible text rather than look up facts — the kinds of hallucination you'll meet in coding and apps, and practical ways to reduce it: grounding, tools, structure, checks and room to say 'I don't know'.