How to Get a Claude API Key (and Keep It Safe)

Where Claude API keys come from, the three key types, expiration and workspaces, how to test a key and use it with Claude Code, and how to store, rotate and revoke keys without breaking anything.

8 min read

You get a Claude API key in the Claude Console. Sign in at platform.claude.com, open Settings, then API keys, and click Create key. You name the key, choose when it expires, link it to yourself or to a service account, and optionally tie it to one workspace. The Console shows the full key, which starts with sk-ant-, exactly once; copy it into a secrets manager or an environment variable named ANTHROPIC_API_KEY, because it cannot be shown again. The API is billed separately from Claude’s Pro, Max, Team and Enterprise plans. The rest of this guide covers the choices on that form and how to keep the key from leaking, as Anthropic documents them on September 30, 2026.

What you do with the key once you have it, the Messages API, models and rate limits, is in the Claude API guide.

Pick a key type first

Anthropic’s page on getting your Claude API key (opens in a new tab) now asks you to choose what the key acts as. The choice decides when the key stops working:

  • Personal key: acts as you, with your role. Use it for your own development and scripts. It stops working when you leave the organization and is not restored if you are invited back.
  • Service account key: acts as a service account an admin creates for a workload, such as a CI pipeline or a production service. It keeps working when the person who made it leaves.
  • Workspace key: the older kind, owned by no one and tied to one workspace. It still works, but Anthropic calls it legacy and suggests personal or service account keys, which cannot outlive the people and workloads they belong to.

If the Create key button is grayed out, your Console role does not allow it. Ask an organization admin to change your role or to create a service account key for you.

Create the key, step by step

  1. Go to platform.claude.com and sign in, or create a Console account.
  2. Open Settings, then API keys, and click Create key.
  3. Name it for where it will live, such as “billing-report-prod”, so a leaked or unused key is easy to trace later.
  4. Choose an expiration (next section).
  5. Set Linked account to yourself or to a service account, and choose a workspace if the key should work in only one.
  6. Copy the key straight into your secrets manager or environment. If you lose it, create a new one; the Console cannot show it again.

Choose an expiration

The authentication guide (opens in a new tab) lists the options: 3 hours, 1 day, 7 days, 30 days, a custom length, or Never for keys kept in a secrets manager that you rotate yourself. An organization can set a maximum, which removes Never. The expiration is fixed when the key is created and cannot be changed later. Anthropic emails the key’s creator 7 days ahead for keys that live at least 14 days, and 1 day ahead for keys that live at least 7 days; shorter keys expire without warning. After expiry, requests fail with 401 authentication_error and the key cannot be revived.

A short expiration suits a key you are testing with. For a production service, a longer key plus a rotation habit, or no static key at all (see “Rotate and revoke” below), is the usual pattern.

Workspaces: one key per purpose

Workspaces split one organization into separate areas with their own members, keys and limits. Every organization has a Default Workspace; admins can create more, up to 100 by default. Anthropic’s workspaces documentation (opens in a new tab) suggests development, staging and production workspaces, each with its own spend and rate limits set below the organization’s, so a runaway test cannot eat production’s share.

  • A key tied to one workspace always runs there. A key that works across several workspaces must send an anthropic-workspace-id header on every request, or the API answers 400.
  • Workspace roles decide who can make keys: Workspace Developer and Workspace Limited Developer can create and manage keys, Workspace User can only use the playground, and Workspace Admin controls the workspace.
  • Archiving a workspace archives every key made for it within seconds, and cannot be undone.
  • The first time someone signs in to Claude Code with a Console account, Anthropic creates a Claude Code workspace and mints a per-user key there. You cannot create keys in it by hand, and it is the only workspace with per-user monthly spend limits.

Test that a key works

The quickest check sends no prompt at all. Listing the available models proves the key is accepted:

Terminal
export ANTHROPIC_API_KEY="sk-ant-..."   # paste, then clear your shell history

curl https://api.anthropic.com/v1/models \
  -H "x-api-key: $ANTHROPIC_API_KEY" \
  -H "anthropic-version: 2023-06-01"

A list of models means the key works. 401 authentication_error means it is wrong, expired, disabled or deleted. A 400 asking for anthropic-workspace-id means it is a multi-workspace key and the request needs that header.

Claude Code with an API key

Claude Code does not need an API key: most people sign in with a Claude subscription. An API key is for billing usage to a Console organization instead. According to Claude Code’s authentication docs (opens in a new tab), when ANTHROPIC_API_KEY is set:

  • In an interactive session, Claude Code asks once whether to use the key and remembers your answer. The “Use custom API key” toggle in /config changes it later.
  • With claude -p, the key is always used when it is present.
  • An approved key wins over a subscription login, so usage is billed to the key’s organization even if you also pay for Pro or Max. Run /status to see which credential is active, and unset ANTHROPIC_API_KEY to fall back to your subscription.
  • The VS Code extension, the Agent SDK and GitHub Actions read the same variable, so a key in your shell profile follows you into the editor. Claude Desktop and cloud sessions do not read it.
  • For keys that rotate, the apiKeyHelper setting runs a script that returns a fresh key, for example from a vault, so nothing static sits in your profile.

Store it where it cannot leak

Anthropic’s help article on API key best practices (opens in a new tab) compares a key to a credit card number: anyone holding it can run up charges on your account. Its advice, in short:

  • Keep keys in environment variables or a secrets manager, never in source code. If you use a .env file, add it to .gitignore before the first commit.
  • Give development, testing and production separate keys, so one leak does not expose everything.
  • Never paste a key into a chat, an email, a support ticket or a third-party tool’s plain-text field.
  • Turn on secret scanning in your source control and add a scanner such as Gitleaks to CI.
  • Watch usage and logs in the Console, and set a spend limit you would notice being hit.

There is one safety net: Anthropic is a GitHub secret scanning partner, so a Claude API key pushed to a public GitHub repository is reported to Anthropic, which deactivates it automatically and emails you. Treat that as a backstop, not a plan. Never ship a key inside a browser or mobile app either; for iOS and macOS apps Anthropic offers App Attest, which gives each genuine install a short-lived token instead.

Rotate and revoke

  1. Create the new key with the same type, workspace and a clear name.
  2. Deploy it wherever the old one lived: the ANTHROPIC_API_KEY variable, the secrets manager entry, the CI secret.
  3. Confirm requests succeed with the new key.
  4. Disable the old key, which is reversible, then delete it once nothing complains. Deleting is permanent.

Anthropic’s help center suggests a fixed schedule, for example every 90 days. If you suspect a leak, skip the schedule and disable or delete the key at once. Admins can list every key with its expiry through the Admin API to spot old ones. For production workloads on AWS, Google Cloud, Azure, Kubernetes or GitHub Actions, Workload Identity Federation replaces the static key entirely: the workload trades its own identity token for a short-lived Claude API token, and there is nothing to rotate.

The same habits for board tokens

An AI assistant that reaches your task board holds a credential too, and the same rules apply. fenbs gives each connection its own: a sign-in through your browser for clients that can do OAuth, or a token issued by hand under Settings, “Connect an AI assistant”, with a name, the scopes it may use and an optional expiry. It is shown once, it can never do more than your own role allows, and revoking it under Settings stops that assistant without touching anything else. A rotation reminder can sit on the board as a task, but fenbs has no due dates, so the date itself belongs in the key’s expiry or your calendar.

Related

The API itself, models and rate limits: Claude API guide. Keys inside an agent: the Claude Agent SDK. How fenbs tokens are scoped: assistant tokens and scopes and giving an AI agent access to your board.

Questions people ask.

Is a Claude API key free?

Creating a key costs nothing, but calls made with it are billed to your Claude Console organization. API usage is separate from Claude subscriptions: a Pro, Max, Team or Enterprise plan does not include it.

Can I see my Claude API key again after creating it?

No. The Console shows the full key only once, when you create it. If you lose it, create a new key and delete the old one.

Does Claude Code need an API key?

No. You can sign in with a Claude Pro, Max, Team or Enterprise account instead. If ANTHROPIC_API_KEY is set and you approve it, Claude Code uses the key and bills its Console organization rather than your subscription.

What happens when a Claude API key expires?

Requests made with it fail with a 401 authentication error, and the key cannot be reactivated. Create a new key and deploy it. Anthropic emails the creator before expiry for keys with a lifetime of at least 7 days.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.