Is security of your API key important?

Janner wrote 4 years ago: 1

I was thinking about utilising the RSS feeds that are available here to use in Inoreader or Feedly.  Given that these are web based apps, your RSS feed (which includes your API) will be visible to anyone that stumbles across it.  

I know keys can be reset, but I'm thinking that exposing your API key in this manner is not really a good idea.

Any thoughts or counter arguments, especially from anyone that already uses the RSS feed functionality?


david wrote 4 years ago: 1

It's not possible to do any permanent harm to your account using the API, such as changing your password or email address. But if someone wanted to annoy you they could use it to do something like remove all your follows and votes..

Are you sure that this setup would expose your API key to any (public) visitor though? I don't know Inoreader and Feedly, but I'd be surprised if they expose your API feed URLs to the general public.

Try 30 days of free premium.