Something in your stack wants YouTube data. A website feed, a dashboard, a creator list, or a plugin that refuses to work until you paste in a key.
A YouTube API key is a free credential from Google Cloud that lets your app read public YouTube data through the YouTube Data API v3.
Getting one takes about five minutes. But, what happens after is the part most guides skip. Since June 1, 2026, Google caps YouTube search at 100 calls a day per project. The key is free. The quota is the bill.
Below, I show you how to create a YouTube API key, how to lock it down, what the quota buys, and when to skip it.
What is a YouTube API key?
A YouTube API key is a long string, starting with “AIza”, that identifies your Google Cloud project whenever your app asks YouTube for data.
Every request carries the key. Google uses it to check that the request is allowed and to count it against your project’s daily quota.
A key only reads public data. Public videos, channels, playlists, comments and search results. It can’t see private data, and it can’t change anything on a channel.
What the YouTube Data API can do
The YouTube Data API v3 is Google’s official interface to YouTube. So if you’re wondering whether YouTube has an API, it has several, and the Data API is the one most tools mean when they ask for a key.
With a YouTube Data API key, you can:
- Search videos by keyword or hashtag (
search.list) - Pull video details like title, description, views, likes and duration (
videos.list) - Get channel stats like subscriber and video counts (
channels.list) - List the videos in a playlist (
playlistItems.list) - Read public comments on a video (
commentThreads.list)
That covers most website feeds, dashboards and creator research tools.
YouTube API key vs. OAuth 2.0
A key isn’t the only credential Google offers. For anything that belongs to a signed-in user, you need OAuth 2.0 instead.
| Task | API key | OAuth 2.0 |
|---|---|---|
| Read public videos, channels and playlists | Yes | Yes |
| Search YouTube | Yes | Yes |
| Upload, update or delete videos | No | Required |
| Read a channel’s private videos | No | Required |
| Manage comments, playlists or subscriptions | No | Required |
| YouTube Analytics API (watch time, audience data) | No | Required |
The rule is simple. Public data needs a key. Private data or any change needs OAuth. Google states that write operations like insert, update and delete always require user authorization.
This guide focuses on the key, since that’s what most website tools and plugins ask for.
How to get a YouTube API key
All you need is a Google account. Here’s how to get a YouTube API key in five steps.
1. Create a Google Cloud project
Go to console.cloud.google.com and sign in. Click the project dropdown at the top, choose New project, give it a clear name like “website-youtube-feed”, and click Create.
Use one project per app. Quota is counted per project, so separate projects keep one tool from draining another.
2. Enable the YouTube Data API v3
In your new project, open APIs & Services > Library. Search for “YouTube Data API v3”, open it and click Enable.
Skip this step and every request fails with an “API not enabled” error, even with a valid key.
3. Create the API key
Open APIs & Services > Credentials. Click Create credentials and select API key.
Google generates the key and shows it in a dialog. Copy it somewhere safe. That’s your YouTube API key. Some tools call it a YouTube Data API v3 key. It’s the same thing.
4. Restrict the API key
An unrestricted key works for any Google API, from anywhere. Click the key’s name on the Credentials page and add two kinds of limits:
- Application restrictions. Pick one type: websites (HTTP referrers), IP addresses, Android apps or iOS apps. Google allows only one type per key.
- API restrictions. Choose Restrict key and select YouTube Data API v3 only.
Click Save. If you want to test the key in your browser first (step 5), save the API restriction now and add the application restriction after the test.
5. Test the API key
Paste this into your browser, with your key at the end:
https://www.googleapis.com/youtube/v3/channels?part=snippet,statistics&forHandle=@GoogleDevelopers&key=YOUR_API_KEY
If you see JSON with the channel’s title and statistics, your key works. If you see an error, jump to the errors table below.
One catch: a browser test only works on a key without application restrictions. A URL typed into the address bar sends no referrer, so a key limited to websites returns “Requests from referer
So either run this test before you add application restrictions in step 4, or test from the site or server the key is restricted to.
How to find your YouTube API key
Lost it? Open the Google Cloud console, select the right project in the dropdown, and go to APIs & Services > Credentials.
Your keys are listed under API keys. Click Show key to copy one.
Rename your keys with the app and site they belong to. “API key 1” means nothing six months from now.
Is the YouTube API key free?
Yes. The key costs nothing, and there’s no paid plan for the YouTube Data API. You don’t pay per call, and Google doesn’t sell extra usage. That’s the whole story on YouTube Data API pricing.
The real price is quota. Every project gets a daily allowance. When it runs out, requests fail until it resets, and the only way to get more is to apply for it.
So the useful question is “how far does the free quota go?”
YouTube API quota in 2026
Quota buckets after June 2026
On June 1, 2026, Google split the YouTube Data API quota into separate buckets. Search and uploads now have their own daily limits, apart from everything else.
| Quota bucket | Default daily limit | Cost per call |
|---|---|---|
Search queries (search.list) |
100 calls | 1 |
Video uploads (videos.insert) |
100 calls | 1 |
| All other methods | 10,000 units | 1 to 50 |
If a tutorial tells you a search costs 100 units out of 10,000, it’s describing the old model.
Quota cost per method
| Method | What it does | Cost |
|---|---|---|
videos.list |
Video details and stats | 1 unit |
channels.list |
Channel details and stats | 1 unit |
playlistItems.list |
Videos in a playlist | 1 unit |
commentThreads.list |
Public comments | 1 unit |
search.list |
Search results | 1 call from the search bucket |
videos.update |
Edit a video (OAuth) | 50 units |
Reads are cheap. Writes cost about 50 units each.
What 10,000 units actually buys
Here’s our math, based on Google’s published quota costs:
- Search tops out at 5,000 results a day. That’s 100 calls with the maximum of 50 results each. Leave
maxResultsat its default of 5, and it’s 500 results a day. - One hashtag uses nearly the whole search bucket. Checking a campaign hashtag every 15 minutes takes 96 searches a day. A second hashtag won’t fit.
- A live website feed breaks at around 10,000 views a day. If your page calls
videos.liston every visit with no caching, each view costs about 1 unit. And the key sits in your page source for anyone to copy.
For one app that caches its results, the free quota is plenty. For hashtag monitoring or high-traffic pages, it runs out fast.
How to request more quota
When the defaults aren’t enough, fill out the YouTube Data API Services Audit and Quota Extension Form, linked from the quota section of the YouTube Data API docs.
Google reviews your use case and checks that your app follows the YouTube API Services Terms of Service. Plan ahead. Approval isn’t instant, and it isn’t guaranteed.
What marketers use a YouTube API key for
Most business owners who search for a YouTube API key aren’t building an app. They have one of four jobs:
| Job | With your own YouTube API key | With EmbedSocial |
|---|---|---|
| Show YouTube videos on your website | Build a feed, cache results, hide the key, handle quota errors | Paste a channel URL, embed one snippet |
| Collect creator and customer videos by hashtag | Work within 100 searches a day | Connect a #hashtag source |
| Find creators for outreach | Script search results into a spreadsheet | Run a ready-made MCP automation into Google Sheets |
| Turn video testimonials into sales material | Custom code plus quota planning | Ask Claude or ChatGPT through the EmbedSocial MCP |
If your job is on this list, the key is the hard way to do it. If you’re building a real product on YouTube data, keep the key and read the security section next.
YouTube API key security
A common question on Reddit: can you put a YouTube API key in a public repo or in your website’s code? No. Anyone who copies it can spend your quota.
Google’s own guidance is direct: “Don’t include API keys in client code or commit them to code repositories.” Call the API from your server, cache the response, and send your site the cached data instead.
Then lock the key down on the Credentials page. Restrict it by application to the websites, IP addresses or apps that should use it, and by API to YouTube Data API v3 only. A leaked key with both limits is far less useful to whoever took it.
A YouTube API key doesn’t expire on its own. It works until you delete or regenerate it, so rotate it yourself. If a key leaks, create a new one, update your app, then delete the old key. Delete keys you no longer use while you’re there.
YouTube API key errors
| Error | Likely cause | Fix |
|---|---|---|
| 400: “API key not valid” | Typo, extra space or deleted key | Copy the key again from Credentials |
| 403: API “has not been used in project” or “is disabled” | YouTube Data API v3 isn’t enabled | Enable the API in the API Library, wait a few minutes |
403: quotaExceeded |
Daily quota used up | Wait for the reset, cache results, or request more quota |
| 403: “Requests from referer are blocked” | Key restriction doesn’t match your site, or the request has no referrer (<empty>) |
Add your domain pattern, like example.com/*, or test from your site |
| 403: forbidden | Request needs OAuth, not a key | Switch to OAuth 2.0 for private data or writes |
| “Missing a valid API key” | The YouTube Data API v3 requires an API key, and none was sent | Add &key=YOUR_API_KEY to the URL |
Most errors come from steps 2 and 4. Check that the API is enabled and your restrictions match where the request comes from.
YouTube API key alternative: EmbedSocial
If your job is showing, collecting or analyzing YouTube videos, EmbedSocial connects to YouTube for you. No Google Cloud project, no quota math, no key to hide.
EmbedSocial connects through the official YouTube API Services, as set out in our terms of service.
YouTube widgets without a key
Paste a YouTube URL and pick a source type: channel, playlist, #hashtag, Shorts, individual videos or Live. Then choose a widget template and embed it.
YouTube sources are available on the Pro plan and above, and #hashtag sources start on Pro Plus. Check our official YouTube widget page.
Once connected, EmbedSocial checks your source on a schedule and pulls new videos in, so your widget updates without touching the embed code.
Due to YouTube API limitations, posts from YouTube update every 24 hours on Pro and Pro Plus. Premium and Enterprise plans have a faster refresh rate.
AI widget builder
Describe the design you want in a prompt, and the AI widget builder generates it. It can also detect and apply your website’s brand colors.
Embed YouTube videos on any website
YouTube widgets can be embedded on WordPress, Shopify, Webflow, Wix, Squarespace and more, plus React, Vue and Angular apps.
Step-by-step guides:
Shoppable YouTube widgets
Tag products in widget content so viewers can follow a link to the product page. Shoppable widgets are available on every plan, and catalog import starts on Pro.
YouTube MCP for Claude and ChatGPT
Connect EmbedSocial to Claude or ChatGPT and pull videos, creators and hashtag results from a prompt. It works through your EmbedSocial account, not a Google key.
Ready-made automations include extracting YouTube creators by hashtag into Google Sheets and turning YouTube video testimonials into a Gamma deck. Find more on our YouTube MCP page.
EmbedSocial API
Need the data in your own app? The EmbedSocial API gives you one key for YouTube, Instagram, Facebook, LinkedIn and Vimeo content. It’s available on Premium and Enterprise plans.
It imports public YouTube videos only. Live and private videos aren’t pulled.
Should you get a YouTube API key?
Get one if you’re building an app on YouTube data. It’s free, it takes five minutes, and the quota covers one app that caches its results. Restrict it and keep it on your server.
Skip it if you only want to show, collect or analyze YouTube videos. A hashtag campaign can use up the 100 daily search calls on its own, and a busy website feed with no cache can burn through the 10,000 units meant for everything else. EmbedSocial handles the connection, the sync and the embed for you.
