> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.vapi.ai/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.vapi.ai/_mcp/server.

# API keys

> API keys authenticate requests to Vapi. Learn where to find public and private keys, choose the correct type, restrict access, and store each key securely.

> **Warning**
>
> Never expose a private API key in browser or mobile app code, logs, screenshots, a source-code repository, or paste it in an agent chat. Store private keys in a server-side secret manager or environment variable.

A Vapi API key is a credential that authorizes an application to access your Vapi organization. Use a public API key for supported client-side integrations and a private API key for server-side requests.

This guide covers API keys issued by Vapi. To connect accounts from model, voice, transcriber, and telephony providers, see [Provider keys](/customization/provider-keys).

## How it works

Every API key belongs to one Vapi organization. Choose the key type based on where your application runs, then limit the key to the origins and assistants that need access.

| Key type        | Use it for                                               | Where to store it                                  |
| --------------- | -------------------------------------------------------- | -------------------------------------------------- |
| Public API key  | Client-side Vapi SDKs and web integrations               | Client-side application configuration              |
| Private API key | Vapi REST API, server SDKs, and server-side integrations | Server-side secret manager or environment variable |

## Prerequisites

* A [Vapi account](https://dashboard.vapi.ai/)
* Access to **API Keys** for your Vapi organization

## Create an API key

#### Open API Keys

Open the [Dashboard](https://dashboard.vapi.ai/org/api-keys), then select **API Keys**.

![Complete Dashboard API Keys page with the expanded sidebar and private and public API key sections](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/vapi.docs.buildwithfern.com/ee7baf874743fea650fd44bd9cbde865bbaeb0b278e268649cb0130208b00108/static/images/security-and-privacy/api-keys/api-keys-overview-sidebar-redacted.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20261003%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20261003T021856Z&X-Amz-Expires=604800&X-Amz-Signature=bee954fd8b16a64b2b0d56fa08a374e50e6edfa9c3ebb518dcc68ad00f1be092&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

#### Choose a key type

Choose **Private API Keys** for server-side access or **Public API Keys** for client-side SDK access.

#### Start creating the key

In the section for your chosen key type, select **Add Key**.

#### Name the key

Enter a descriptive name in **Name**.

#### Restrict access

For a public key, enter the URLs that may use the key in **Allowed Origins**. In **Allowed Assistants**, select the assistants the key may access. Enable **Transient Assistant** only when the application needs to create calls with [transient assistants](/assistants/concepts/transient-vs-permanent-configurations).

For example, add `https://app.example.com` for a production web application.

![Complete New Public API Key form with the expanded Dashboard sidebar, name, allowed origins, allowed assistants, and transient assistant settings](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/vapi.docs.buildwithfern.com/f758cb9d264a95b84af9e819fd310f599d4bf128b451f46f938158ad682d3bed/static/images/security-and-privacy/api-keys/new-public-api-key-sidebar.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20261003%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20261003T021856Z&X-Amz-Expires=604800&X-Amz-Signature=c2a541cda32cdab1311c06032763d33636306c84eac2b5609ae4c46568f83615&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

#### Create and store the key

Select **Create Private Token** or **Create Public Token**. Select **Copy ID** next to the new key, then store the copied value in the appropriate location for that key type.

> **Note**
>
> Use separate keys for development, staging, and production. Give each key only the access its application needs.

## View or copy a key

Open the [Dashboard](https://dashboard.vapi.ai/org/api-keys), then select **API Keys**. Find the key under **Private API Keys** or **Public API Keys**.

* Select the eye icon next to the masked key value to view the key.
* Select the copy icon next to the masked key value to copy the key.

## Use a public API key

Pass a public API key to the [Vapi Web SDK](/quickstart/web) to start a browser-based voice call with an assistant:

```typescript
import Vapi from "@vapi-ai/web";

const vapi = new Vapi("YOUR_PUBLIC_API_KEY");
vapi.start("YOUR_ASSISTANT_ID");
```

Replace `YOUR_PUBLIC_API_KEY` and `YOUR_ASSISTANT_ID` with values from your Vapi organization.

> **Note**
>
> Public API keys are visible in client-side code. Restrict them to the required origins and assistants. For short-lived or user-specific access, use [JWT authentication](/customization/jwt-authentication).

## Test a private API key

Send a private API key in the `Authorization` header as a bearer token. This request only lists the assistants in your organization and does not modify them:

```bash
export VAPI_PRIVATE_API_KEY="YOUR_PRIVATE_API_KEY"

curl https://api.vapi.ai/assistant \
  -H "Authorization: Bearer $VAPI_PRIVATE_API_KEY"
```

Replace `YOUR_PRIVATE_API_KEY` with your private API key. Do not add the real value to a script or commit it to version control.

## Find your organization ID

Some integrations require your organization ID in addition to an API key.

#### Open General Settings

Open the [Dashboard](https://dashboard.vapi.ai/). Select your organization name in the upper-left corner, then select **Settings**.

Under **Organization Settings**, select **General Settings**.

![Complete Dashboard General Settings page with the main and Settings sidebars expanded and organization values blurred](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/vapi.docs.buildwithfern.com/cea1bb9e9ae506067e5e8b617163ea1bccbba0da4fbc24ebf79b24b569d9d6a9/static/images/security-and-privacy/api-keys/general-settings-sidebar-redacted.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20261003%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20261003T021856Z&X-Amz-Expires=604800&X-Amz-Signature=fceb52c8333e33ba99b4bdedfe593981289a6e538732dcd45d55941c25bad711&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

#### Copy the organization ID

Locate **Organization ID**, then select **Copy to clipboard**.

## Verify it works

Run the list-assistants request with a private API key. A successful request returns a JSON list containing the assistant you created. A `401` response means the key is missing, invalid, or unavailable to the organization making the request.

Confirm that the new key also appears under **Private API Keys** or **Public API Keys** in the Dashboard.

## Related

#### [Web widget](/chat/web-widget)

Use a public API key in a client-side Vapi integration.

#### [Server SDKs](/server-sdks)

Use a private API key with a Vapi server SDK.

#### [Provider keys](/customization/provider-keys)

Connect credentials from supported third-party providers.

#### [JWT authentication](/customization/jwt-authentication)

Authenticate end users without exposing a private API key.

#### [CLI authentication](/cli/auth)

Use OAuth to sign in when working interactively with the Vapi CLI.

#### [Single Sign-On](/security-and-privacy/sso)

Use SAML or OIDC to manage enterprise team access to the Dashboard.