API keys
An API key authenticates requests against the account it was created in. It’s the right credential when your application works with your own Mailchimp data. To create one, see Generate your API key.
What a key grants
A key carries full access to the account it belongs to. There is no way to issue a read-only key or restrict one to particular endpoints, so treat a key the way you’d treat a password.
Keys don’t expire. A key stays valid until you delete it, or until the user who created it is removed from the account; see User access and revocation.
Where keys can’t be used
Because a key grants full account access, two environments are ruled out:
- Browsers. Mailchimp does not support client-side calls to the Marketing API using CORS requests. A key in front-end code is readable by anyone who loads the page.
- Mobile apps. A key shipped inside a distributed binary can be extracted from it. For iOS and Android, use the Mobile SDK, which is built against a mobile-focused subset of the API.
Both cases have the same shape: the credential ends up somewhere you don’t control. Keep keys on a server you own.