DevNet Associate (DEVASC) v1.0Understanding and Using APIsMedium

A developer is writing a Python script to interact with a Cisco API that requires an API key for authentication. The API key is sensitive and should not be hardcoded in the script or committed to version control. Which is the most secure and recommended method for the script to access the API key at runtime?

  1. AEmbed the API key directly into the Python script as a global variable.
  2. BStore the API key in a plain text file (.txt) alongside the script and read it.
  3. CStore the API key as an environment variable and access it using `os.environ`.
  4. DPrompt the user to manually enter the API key every time the script runs.
Show answer & explanation

Correct answer: C. Store the API key as an environment variable and access it using `os.environ`.

Storing sensitive information like API keys as environment variables is a common and secure practice. It keeps the key out of the codebase and version control, allowing it to be managed independently for different environments without being exposed.

Why the other options are wrong

  • A. Hardcoding the API key makes it vulnerable if the code is ever exposed or committed to version control.
  • B. Plain text files are not secure and can easily be read by anyone with access to the file system.
  • D. Manually entering the key is impractical for automated scripts and can be tedious for repeated execution.

Secure API Key Storage

Best practices for storing and accessing API keys involve methods that prevent hardcoding, exposure in version control, and unauthorized access, typically by externalizing them from the application code.

  • Never hardcode API keys directly in source code.
  • Avoid committing API keys to version control systems (e.g., Git).
  • Environment variables are a common and secure method.
  • Secret management services (e.g., HashiCorp Vault, AWS Secrets Manager) provide advanced protection.

Memory trick: Environment variables Keep Secrets Safe Every time.

More Understanding and Using APIs questions