Concepts / HTTP Request Headers and Query Parameters

HTTP Request Headers and Query Parameters

API keys are the mechanism vendors use to identify users and monitor their service consumption.

  • Programming

The Identity Problem

When your client sends a request to a vendor's API, the vendor needs a way to know who is making the call. Without identification, the vendor cannot distinguish one user from another. That makes it impossible to track which account is consuming the service or to enforce usage policies for that account.

An API key is a unique identifier that you include with an API request to tell the vendor who you are. Each API key is associated with a user account and is validated on every request.

A useful analogy is a membership card. When you present the card to a vendor, the vendor can look up your account and keep track of what you are doing. An API key serves a similar identification purpose for requests sent to an API.

Request Path to Account

An API key travels as part of the request sent by your client. The source identifies request headers, query parameters, and the request body as places where a vendor may extract the key. This article focuses on the first two locations: headers and query parameters.

sendsarrives atlooks up keymaps toClientsends requestHTTP requestcontains API keyVendor serverextracts keyValid key databasekey lookupUser accountassociated account
Where does the API key travel in the request, and how does the vendor connect it to an account?

The vendor's server receives the request and extracts the API key. It then looks up the key in its database of valid keys. If the key is found and is valid, the server retrieves the associated user account. The request is now connected to an identified account rather than being an unattributed call.

Headers and Query Parameters

Request locationWhat the source establishesVendor action
Request headersAn API key may be included hereThe vendor extracts and validates the key
Query parametersAn API key may be included hereThe vendor extracts and validates the key

The important idea is not that the key is a separate request. The key travels with the request, and the vendor extracts it from the location expected by that API. Whether the key is placed in a header or a query parameter, the vendor uses it to look up the associated account and validate the request.

Validation and Usage Tracking

After identifying the account, the vendor can process the request with knowledge of who is using the service. After processing, the vendor increments the usage counter so that the request becomes part of the account's usage record.

key checkedvalid accountrecord requestinform enforcementIncoming requestincludes API keyValidated keyaccount identifiedProcessed requestservice respondsUsage counterincrementedUsage policylimits and tier rules
What changes after requests arrive with the same API key, and how can the vendor apply usage policies?

The counter gives the vendor a record of how much the identified account has used the service. Vendors use this information to enforce rate limits, monitor overall usage, track usage for billing, and identify when an account may be approaching a billing threshold.

Multiple Keys and Service Tiers

Separating Application Usage

A single user owns a web application, a mobile application, and a data analysis script. The user assigns a different API key to each application.

Identify the account: Each key is associated with the same user account, so the vendor can identify the user behind every request.

Track keys independently: Because each application uses a different key, the vendor can track the requests from the web application, mobile application, and analysis script separately.

Compare usage: Independent tracking shows which application is consuming the most resources and helps the user optimize usage.

Apply account policies: The vendor can use the identified account and its service rules when enforcing limits, managing tiers, or tracking usage for billing.

Multiple API keys allow more granular monitoring within one user account. A key can also be revoked without affecting the other keys.

identifieshasdefinesAPI keyincoming identifierUser accountownerService tierfree or premiumUsage limitsrequest policy
How does an API key connect an incoming request to an account's service tier and usage rules?

Service tiers are another reason the key matters. A vendor might offer a free tier with limited requests per day and a premium tier with higher limits. The API key lets the vendor determine which account and tier are connected to the request, then apply the relevant usage policies.

Common Misunderstandings

  • Assuming the vendor can track usage without identifying the caller.

    Without identification, the vendor cannot connect the request to a user account or distinguish one user's consumption from another's.

    Fix: Include the API key with the request in the location specified by the vendor, such as a request header or query parameter.

  • Treating all API keys owned by one user as one independently tracked key.

    A single user can own multiple API keys, and each key is tracked independently.

    Fix: Use the independent key records to understand which application is consuming resources.

  • Ignoring rate limits and service tiers after obtaining a valid key.

    Vendors use API keys to enforce rate limits and manage free and premium service tiers.

    Fix: Plan for rate limits and implement error handling for situations in which usage exceeds the applicable limit.

  • Assuming the key's location is interchangeable for every API.

    The vendor extracts the key from the location expected by its API.

    Fix: Follow the vendor's specified request format.

Applying the Model

MEDIUM

A vendor receives three requests: two use one API key and one uses a second API key belonging to the same user account. Explain what the vendor can identify, what it can track separately, and how the account's service tier could affect request policies.

Hints
  • Start with the relationship between an API key and a user account.
  • Remember that multiple keys belonging to one account can be tracked independently.
  • Connect the identified account to rate limits and service tiers.

What do you think happens?

A user has one API key for a web application and another for a mobile application. If the web application makes 1,250 requests and the mobile application makes 3,840 requests, which application can the vendor identify as using more resources?

  • The web application
  • The mobile application
  • The vendor cannot distinguish them
  • Both applications must have identical usage
Reveal answer

Answer: The mobile application.

Each key is tracked independently, so the vendor can associate the two usage totals with their respective applications.

Practical Design Notes

When building an application that uses a vendor API, plan how you will obtain, store, and use the API key. Also anticipate the vendor's rate limits and implement error handling for situations in which those limits are exceeded. If you use multiple keys for different applications, independent tracking can help you see which application is consuming the most resources.

The API key is not merely a value attached to a request. It connects the request to an account, allowing the vendor to identify the caller, record usage, apply rate limits, manage service tiers, and track usage for billing.

Key Takeaways

  • An API key identifies the user account associated with an API request.
  • A vendor can extract and validate the key from a request header, query parameter, or, depending on the API, the request body.
  • After identifying the account, the vendor can record usage, enforce rate limits, and track usage for billing.
  • Free and premium service tiers can have different request limits, and the API key connects a request to the applicable account policies.
  • Multiple keys owned by one user can be tracked independently, allowing usage to be separated by application.