Tactical Engine
AboutServicesPortfolioBlogReviewsContactCall 714 924 4604
Home/Blog/Securing Your Google Maps API Key Using HTTP Referrer Restriction

Securing Your Google Maps API Key Using HTTP Referrer Restriction

Securing Your Google Maps API Key Using HTTP Referrer Restriction

Keeping an API key confidential is the first line of defense, but Google gives you a second layer worth using: HTTP referrer restriction. If your site does not have a Maps API key yet, get one first, then come back and lock it down.

Step 1

Open the Google Cloud Platform console and go to API & Services → Credentials.

Google Cloud Platform Credentials screen

Step 2

Select the specific API key you want to restrict.

Selecting an API key in Google Cloud

Step 3

Under Application restrictions, choose HTTP referrers (websites) and enter your domain in the format Google expects.

Setting HTTP referrer restrictions on a Google API key

The change takes about five minutes to propagate. After that, the key only works from your domain, and anyone who tries to use it elsewhere gets denied automatically.

Keep reading

More from the blog

Ready when you are

Want help with this on your site?

Free consultation, straight answers, and a real partnership.

Start with a free consultation

Tell us about your business and we'll tell you exactly where the easy wins are.

Call 714 924 4604Send us a message