The two rules
Create keys only in the official console. Keep them only on servers.
Get your key from console.perplexity.ai, never from a third-party site or seller. Store it in an environment variable or secrets manager, and never put it in website, mobile app or public code.
Step by step
How to create a Perplexity API key
Sign in to the API console
Go to console.perplexity.ai and sign in with your Perplexity account. Make sure you’re on the real perplexity.ai domain before entering anything.
- Use a strong password and turn on two-step verification.
- For a team, use an organisation account, not a personal one.
Add a payment method and credit
The API is pay-as-you-go. Add a card and buy a small amount of credit to start. You can top up later or set up automatic top-ups.
- Start small while you’re testing.
- Turn on usage alerts if available.
Open the API Keys page
In the console, open your project and go to API Keys.
- Create a separate project per app if you run several.
Create a key with a clear name
Click to create a new key and give it a name that says where it’s used, like “blog-chatbot-production”.
- One key per app and per environment (development, production).
- Names make it easy to revoke the right key later.
Copy it and store it safely right away
Copy the key straight into your password manager or secrets manager. Some consoles show a key in full only once, so don’t close the page until it’s saved.
- Never paste it into chat, email, tickets or screenshots.
- Next, put it in an environment variable (below).
Storage
Store your key in an environment variable
The Perplexity SDK reads PERPLEXITY_API_KEY automatically, so your code never needs to contain the key.
# Current terminal session only export PERPLEXITY_API_KEY="your_api_key_here" # Make it permanent (zsh, the macOS default) echo 'export PERPLEXITY_API_KEY="your_api_key_here"' >> ~/.zshrc source ~/.zshrc
# Current PowerShell session only $env:PERPLEXITY_API_KEY = "your_api_key_here" # Save for your user account (open a new window afterwards) setx PERPLEXITY_API_KEY "your_api_key_here"
# .env (never commit this file) PERPLEXITY_API_KEY=your_api_key_here
# .gitignore .env .env.* !.env.example
Use it in Python
# pip install perplexityai python-dotenv
from dotenv import load_dotenv
from perplexity import Perplexity
load_dotenv() # loads PERPLEXITY_API_KEY from .env
client = Perplexity() # reads the key from the environment
reply = client.chat.completions.create(
model="sonar",
messages=[{"role": "user", "content": "Hello!"}],
)
print(reply.choices[0].message.content)Test that it works
curl https://api.perplexity.ai/v1/sonar \
-H "Authorization: Bearer $PERPLEXITY_API_KEY" \
-H "Content-Type: application/json" \
-d '{"model":"sonar","messages":[{"role":"user","content":"Say hello"}]}'In production, use your platform’s secret store instead of a .env file: for example GitHub Actions secrets, Vercel or Netlify environment variables, AWS Secrets Manager, Google Secret Manager or Azure Key Vault.
Architecture
Keep your key out of the browser
Anyone can read the JavaScript in a web page or unpack a mobile app. Put a small server between your users and Perplexity.
A minimal server proxy (Node.js)
// server.js (Node 18+, Express). The key stays on the server.
import express from "express";
const app = express();
app.use(express.json());
app.post("/api/ask", async (req, res) => {
const question = String(req.body.question || "").slice(0, 1000);
const r = await fetch("https://api.perplexity.ai/v1/sonar", {
method: "POST",
headers: {
"Authorization": `Bearer ${process.env.PERPLEXITY_API_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({ model: "sonar", messages: [{ role: "user", content: question }] }),
});
const data = await r.json();
res.json({ answer: data.choices?.[0]?.message?.content, citations: data.citations });
});
app.listen(3000);Do
- Call the API only from your backend
- Limit question length and requests per user
- Require sign-in for heavy features
- Return only what the front end needs
Don’t
- Put the key in React, Vue or plain JavaScript files
- Ship the key inside a mobile app
- Send the key in URLs or query strings
- Log full request headers
Version control
Keep your key out of Git
Add .env to .gitignore before your first commit. Commit a .env.example with placeholder values instead.
Use a secret scanner such as gitleaks as a pre-commit hook to stop keys being committed.
GitHub secret scanning and push protection can block pushes that contain keys.
A key removed in a later commit is still in your history. If a key was ever committed, treat it as leaked and replace it.
API key security checklist
Think your key leaked? Do this now
Leaked keys are found and abused quickly, often within minutes of being pushed to a public repo.
- Delete the key in the API console so it stops working.
- Create a new key and store it in your secrets manager.
- Update every app and server that used the old key, then redeploy.
- Check your usage and billing for calls you didn’t make, and contact Perplexity support if you see any.
- Remove the key from code and history, and add scanning so it can’t happen again.
FAQ
Perplexity API key questions
Where do I get a Perplexity API key?
In the Perplexity API console at console.perplexity.ai. Sign in, add credit, open API Keys and create a new key.
Is the Perplexity API key free?
Creating a key is free, but using the API costs money. You need credit in your account before calls will work. See our API pricing guide.
Can I use my Perplexity Pro subscription for the API?
No. Pro and Max cover the Perplexity apps. API usage is billed separately through the API console.
Can I put my API key in my website’s JavaScript?
No. Anything in front-end or mobile app code can be seen by visitors, who could then use your key and run up your bill. Call the API from your server instead.
What should I do if my API key leaks?
Delete (revoke) it in the API console immediately, create a new key, update your apps, then check your usage for unexpected charges and remove the key from your code history.
How often should I rotate my API key?
A common practice is every 90 days, and immediately whenever someone with access leaves or a leak is suspected.
Why does my key return a 401 error?
The key is missing, mistyped, revoked or sent in the wrong header. Check the environment variable is loaded and that you send Authorization: Bearer YOUR_KEY.
More API guides
Ready
Create your key in the official console
Only create and manage API keys at console.perplexity.ai. This guide never asks for, stores or sells API keys.