Best Practices
Handle your API keys securely. Don’t share your API key with others or expose it in the browser or other client-side code. Here are some general guidelines:- Store API keys in environment variables.
- Never commit API keys to version control.
- Never hard-code API keys in your code or share them publicly.
- Rotate API keys regularly. If an API key hasn’t been used in the last 30 days, consider deleting it to keep your account secure.
You can view an API key only once after you create it.
Key Rotation
Resend API keys don’t expire automatically. Keys remain valid until you manually delete them. Resend includes no built-in expiration date or automatic rotation mechanism, but it’s a good security practice to rotate keys regularly. To rotate an API key:- Create a new key in the API keys Dashboard page or via the API with the same permission level and domain scope as the key you’re replacing.
- Update your services to use the new key. Deploy the change to all environments that reference the old key.
- Verify the new key is working by filtering by API key on the Logs Dashboard page and checking for recent requests.
- Delete the old key once you’ve confirmed the new key is active across all services.