How an API key works
When an app sends a message to a model provider, it includes your API key in the request headers. The provider checks the key, serves the model, and charges the token usage to the account and project the key belongs to.
That means the key is metered: you pay per token on the provider's published rates. It is different from a consumer subscription, which bundles model access into a flat monthly price with no key involved.
An API key is not your password
A leaked API key lets someone spend money on your provider account — it does not expose your email, billing details, or the ability to change your password.
Treat it accordingly: create a dedicated key for each app, set a spend limit on it, and revoke it when you stop using the app. Rotating a key is a one-click action in the provider dashboard.
How to keep an API key safe
Use a dedicated key per application, so revoking one does not break others. Set a usage or spend limit at the provider. Store the key in a password manager rather than a note or a chat message, and never commit it to a repository.
For apps that store keys for you, prefer one that encrypts the key and gives you a clear way to delete it. In MultimodelChat keys are encrypted in a local browser vault (Web Crypto, AES-256) by default, or stored encrypted in the hosted option.