# Overview

The API secret is used for authentication in the most critical parts of the system where access should be limited. For example, the API secret is used in REST APIs and Webhooks mechanisms.

Each environment has one API secret, but it can be changed.

For security reasons, the API secret should be kept in a safe place.

# API secret management

The API secret is available for every environment in the CKEditor Ecosystem customer dashboard. You can find it in the list of environments.

Environment list with API secrets in CKEditor Ecosystem customer dashboard.

Click the “API configuration” button for a particular environment to gain access to the configuration as well as the possibility to change the API secret.

API secret management with the “Refresh API secret” link.

If by any chance your API secret is made public, it should be changed immediately by using the “Refresh API secret” link shown in the image above.