Presumably, they check the referrer HTTP header.
Most users send it. So, if there is:
- The site corresponding to the key can work as usual.
- A site that does not match the key may reject the request.
- Blank , they can work as usual and allow a tiny fraction of people to use the API on the wrong site.
Most site visitors using the wrong key will be blocked, so you should not use the wrong key on the site in the first place.
Quentin
source share