Preventing unauthorised use.
WHY IT MATTERS MOST HERE
A key in a public web page is visible to everyone, and unrestricted use is billed to you.
WHAT HAPPENS WITHOUT RESTRICTIONS
Keys are scraped and used on other sites, at your cost.
WHAT TO RESTRICT BY, FOR WEB
The referring website, listing your domains exactly.
WHAT TO RESTRICT BY, FOR ANDROID
The application package name and signing certificate fingerprint.
WHAT TO RESTRICT BY, FOR iOS
The bundle identifier.
WHAT TO RESTRICT BY, FOR SERVERS
Address ranges.
WHAT ELSE TO RESTRICT
Which APIs the key may call.
WHY
A key intended for map display should not be usable for expensive services.
WHAT TO USE
Separate keys per platform and per purpose.
WHY
Restrictions differ, and a compromised key can be replaced without affecting everything.
WHAT TO SET
Daily quotas per key, below what a runaway would consume.
WHAT TO MONITOR
Usage per key, and any unexpected rise.
WHAT TO DO IF A KEY IS MISUSED
Replace it, and tighten restrictions.
WHAT TO NEVER DO
Put a server key in client code.