Independent guide. perplexitiai.com is not affiliated with or endorsed by Perplexity AI, Inc. The official site is perplexity.ai.

How to Create and Secure a Perplexity API Key

Your API key is like a password linked to your billing. This guide shows how to create one in the official Perplexity API console in five steps, then how to store it, keep it out of browsers and Git, rotate it, and what to do if it ever leaks.

The two rules

Create keys only in the official console. Keep them only on servers.

Get your key from console.perplexity.ai, never from a third-party site or seller. Store it in an environment variable or secrets manager, and never put it in website, mobile app or public code.

Step by step

How to create a Perplexity API key

  1. Sign in to the API console

    Go to console.perplexity.ai and sign in with your Perplexity account. Make sure you’re on the real perplexity.ai domain before entering anything.

    • Use a strong password and turn on two-step verification.
    • For a team, use an organisation account, not a personal one.
  2. Add a payment method and credit

    The API is pay-as-you-go. Add a card and buy a small amount of credit to start. You can top up later or set up automatic top-ups.

    • Start small while you’re testing.
    • Turn on usage alerts if available.
  3. Open the API Keys page

    In the console, open your project and go to API Keys.

    • Create a separate project per app if you run several.
  4. Create a key with a clear name

    Click to create a new key and give it a name that says where it’s used, like “blog-chatbot-production”.

    • One key per app and per environment (development, production).
    • Names make it easy to revoke the right key later.
  5. Copy it and store it safely right away

    Copy the key straight into your password manager or secrets manager. Some consoles show a key in full only once, so don’t close the page until it’s saved.

    • Never paste it into chat, email, tickets or screenshots.
    • Next, put it in an environment variable (below).

Storage

Store your key in an environment variable

The Perplexity SDK reads PERPLEXITY_API_KEY automatically, so your code never needs to contain the key.

Terminal
# Current terminal session only
export PERPLEXITY_API_KEY="your_api_key_here"

# Make it permanent (zsh, the macOS default)
echo 'export PERPLEXITY_API_KEY="your_api_key_here"' >> ~/.zshrc
source ~/.zshrc

Use it in Python

Python
# pip install perplexityai python-dotenv
from dotenv import load_dotenv
from perplexity import Perplexity

load_dotenv()            # loads PERPLEXITY_API_KEY from .env
client = Perplexity()    # reads the key from the environment

reply = client.chat.completions.create(
    model="sonar",
    messages=[{"role": "user", "content": "Hello!"}],
)
print(reply.choices[0].message.content)

Test that it works

Terminal
curl https://api.perplexity.ai/v1/sonar \
  -H "Authorization: Bearer $PERPLEXITY_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"model":"sonar","messages":[{"role":"user","content":"Say hello"}]}'

In production, use your platform’s secret store instead of a .env file: for example GitHub Actions secrets, Vercel or Netlify environment variables, AWS Secrets Manager, Google Secret Manager or Azure Key Vault.

Architecture

Keep your key out of the browser

Anyone can read the JavaScript in a web page or unpack a mobile app. Put a small server between your users and Perplexity.

User’s browser No key here Your server holds the key checks input, limits use Perplexity API /v1/sonar question + key answer only answer

A minimal server proxy (Node.js)

server.js
// server.js (Node 18+, Express). The key stays on the server.
import express from "express";
const app = express();
app.use(express.json());

app.post("/api/ask", async (req, res) => {
  const question = String(req.body.question || "").slice(0, 1000);
  const r = await fetch("https://api.perplexity.ai/v1/sonar", {
    method: "POST",
    headers: {
      "Authorization": `Bearer ${process.env.PERPLEXITY_API_KEY}`,
      "Content-Type": "application/json",
    },
    body: JSON.stringify({ model: "sonar", messages: [{ role: "user", content: question }] }),
  });
  const data = await r.json();
  res.json({ answer: data.choices?.[0]?.message?.content, citations: data.citations });
});

app.listen(3000);

Do

  • Call the API only from your backend
  • Limit question length and requests per user
  • Require sign-in for heavy features
  • Return only what the front end needs

Don’t

  • Put the key in React, Vue or plain JavaScript files
  • Ship the key inside a mobile app
  • Send the key in URLs or query strings
  • Log full request headers

Version control

Keep your key out of Git

Ignore .env files

Add .env to .gitignore before your first commit. Commit a .env.example with placeholder values instead.

Scan before you push

Use a secret scanner such as gitleaks as a pre-commit hook to stop keys being committed.

Turn on push protection

GitHub secret scanning and push protection can block pushes that contain keys.

Deleting isn’t enough

A key removed in a later commit is still in your history. If a key was ever committed, treat it as leaked and replace it.

API key security checklist

0%Tick what you already do.

Think your key leaked? Do this now

Leaked keys are found and abused quickly, often within minutes of being pushed to a public repo.

  1. Delete the key in the API console so it stops working.
  2. Create a new key and store it in your secrets manager.
  3. Update every app and server that used the old key, then redeploy.
  4. Check your usage and billing for calls you didn’t make, and contact Perplexity support if you see any.
  5. Remove the key from code and history, and add scanning so it can’t happen again.

FAQ

Perplexity API key questions

Where do I get a Perplexity API key?

In the Perplexity API console at console.perplexity.ai. Sign in, add credit, open API Keys and create a new key.

Is the Perplexity API key free?

Creating a key is free, but using the API costs money. You need credit in your account before calls will work. See our API pricing guide.

Can I use my Perplexity Pro subscription for the API?

No. Pro and Max cover the Perplexity apps. API usage is billed separately through the API console.

Can I put my API key in my website’s JavaScript?

No. Anything in front-end or mobile app code can be seen by visitors, who could then use your key and run up your bill. Call the API from your server instead.

What should I do if my API key leaks?

Delete (revoke) it in the API console immediately, create a new key, update your apps, then check your usage for unexpected charges and remove the key from your code history.

How often should I rotate my API key?

A common practice is every 90 days, and immediately whenever someone with access leaves or a leak is suspected.

Why does my key return a 401 error?

The key is missing, mistyped, revoked or sent in the wrong header. Check the environment variable is loaded and that you send Authorization: Bearer YOUR_KEY.

More API guides

Ready

Create your key in the official console

Only create and manage API keys at console.perplexity.ai. This guide never asks for, stores or sells API keys.