# Confusion about API Authenticated User

**URL:** <https://meta.discourse.org/t/confusion-about-api-authenticated-user/310042>\
**Category:** Development\
**Tags:** rest-api\
**Created:** [May 30, 2024, 11:37pm UTC](https://meta.discourse.org/t/confusion-about-api-authenticated-user/310042 "2024-05-30T23:37:43Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![supermathie](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/supermathie/32/507518_2.png) [@supermathie](https://meta.discourse.org/u/supermathie)\
**Post date:** [May 31, 2024, 2:57am UTC](https://meta.discourse.org/t/confusion-about-api-authenticated-user/310042/2 "2024-05-31T02:57:16Z")

</div>

> [@BrainFried](#):
>
> a headless implementation of discourse to integrate into my frontend

> [@BrainFried](#):
>
> isn’t this easy for a hacker to just modify the api-username in the header to retrieve chat discussions for any user?

An Admin API key is the key to the kingdom

![](https://media.tenor.com/BxBXA_6u-PQAAAAC/lotr-keep-it-safe.gif)

Do not put it anywhere in a frontend app. If you did, I recommend you revoke it immediately.

---

_[View the full topic](https://meta.discourse.org/t/confusion-about-api-authenticated-user/310042)._
