วิธีสร้าง Gemini API Key ใน Google AI Studio

Gemini API Key คือ Credential ที่ใช้ยืนยันและเชื่อม Request จากโปรแกรมของเราเข้ากับ Gemini API โดยสามารถสร้างและจัดการ Key ได้ผ่าน Google AI Studio

สำหรับผู้ใช้ใหม่ Google AI Studio ปัจจุบันสามารถสร้าง Google Cloud Project และ Gemini API Key เริ่มต้นให้อัตโนมัติ หลังยอมรับข้อกำหนดการใช้งาน ส่วนผู้ที่ต้องการ Key ใหม่สามารถเข้าเมนู API Keys แล้วเลือก Create API key

สิ่งสำคัญในปีปัจจุบันคือ Google กำลังเปลี่ยนระบบจาก Standard API Key ไปเป็น Authorization Key หรือ Auth Key โดย API Key ใหม่ที่สร้างใน Google AI Studio จะถูกสร้างเป็น Auth Key โดยอัตโนมัติ ซึ่งผูกกับ Google Cloud Service Account และให้ความสามารถด้าน Access Control ที่ละเอียดกว่า Standard Key เดิม

ขั้นตอนโดยสรุปคือ เข้า Google AI Studio → เปิด Dashboard → API Keys → Create API key → เลือก Project → Copy Key → เก็บเป็น Secret → ตั้ง Environment Variable → ทดสอบ Gemini API

❶ 🔑 Gemini API Key คืออะไร

Gemini API Key คือ Credential สำหรับ Authentication เมื่อ Application ต้องการเรียก Gemini API

ตัวอย่าง Architecture

Application
↓
Gemini API Key
↓
Gemini API
↓
Gemini Model
↓
Response

Key ช่วยให้ Google รู้ว่า Request เกี่ยวข้องกับ Project ใด เพื่อใช้กับเรื่องต่าง ๆ เช่น

  • Authentication
  • Quota
  • Rate Limit
  • Billing
  • Usage Tracking
  • Project Management

ดังนั้น API Key ไม่ใช่ข้อความที่ควรแชร์สาธารณะ

❷ 🆕 ผู้ใช้ใหม่อาจมี API Key อยู่แล้ว

ก่อนกดสร้าง Key ใหม่ ควรตรวจหน้า API Keys ก่อน

Google ระบุว่า เมื่อผู้ใช้ใหม่เริ่มต้น Google AI Studio ระบบสามารถสร้าง

  • Default Google Cloud Project
  • API Key

ให้อัตโนมัติหลังยอมรับ Terms of Service

ดังนั้น Workflow อาจเป็นเพียง

เข้า AI Studio
↓
Dashboard
↓
API Keys
↓
พบ Key เริ่มต้น
↓
Copy

ไม่จำเป็นต้องสร้าง Key หลายอันโดยไม่มีเหตุผล

❸ 🚀 วิธีสร้าง Gemini API Key ใน Google AI Studio

ขั้นตอนสำหรับสร้าง Key ใหม่มีดังนี้

ขั้นที่ 1 เข้า Google AI Studio

ลงชื่อเข้าใช้ด้วย Google Account ที่ต้องการใช้พัฒนา Application

ควรตรวจ Account ให้ถูก โดยเฉพาะคนที่ Login Google หลายบัญชีใน Browser เดียวกัน

ขั้นที่ 2 เปิด Dashboard

ไปยังส่วน Dashboard ของ AI Studio

ขั้นที่ 3 เลือก API Keys

เปิดหน้าจัดการ Gemini API Keys

ขั้นที่ 4 เลือก Create API key

กด

Create API key

ขั้นที่ 5 เลือก Project

เลือก Google Cloud Project ที่ต้องการเชื่อม Key

หากเป็นผู้ใช้ใหม่อาจมี Default Project อยู่แล้ว

ขั้นที่ 6 สร้าง Key

ทำตาม Dialog ของ AI Studio

ขั้นที่ 7 Copy Key

หลังสร้างสำเร็จให้ Copy Key ไปเก็บในตำแหน่งที่ปลอดภัย

ขั้นที่ 8 ตั้ง Environment Variable

เช่น

GEMINI_API_KEY

จากนั้น Application สามารถอ่าน Credential จาก Environment แทนการฝัง Key ลง Source Code

❹ 🛡️ API Key ใหม่เป็น Auth Key

นี่คือการเปลี่ยนแปลงสำคัญที่ Developer ควรรู้

Google กำลังเปลี่ยน Gemini API จาก

Standard API Key

ไปสู่

Authorization Key
หรือ
Auth Key

ปัจจุบัน API Key ใหม่ที่สร้างผ่าน Google AI Studio จะถูกสร้างเป็น Auth Key โดยอัตโนมัติ

Auth Key แตกต่างจาก Standard Key เดิมตรงที่ Key ถูกผูกกับ Google Cloud Service Account

ทำให้ Request สามารถทำงานภายใต้ Identity ที่ชัดเจนขึ้น

❺ 🆚 Standard Key กับ Auth Key ต่างกันอย่างไร

Standard API Key

ใช้เชื่อม Request กับ Google Cloud Project เพื่อ

  • Billing
  • Quota

แต่ไม่ได้ระบุ Identity ของ Caller แบบละเอียดเท่า Auth Key

Authorization Key

ผูกกับ Google Cloud Service Account

ช่วยให้สามารถใช้

  • Identity
  • Access Control
  • Permission

ได้ละเอียดขึ้น

Google ยังระบุว่า Auth Key ใหม่ถูก Restrict ให้ใช้กับ Gemini API โดย Default

จึงเป็นแนวทางที่ Google แนะนำสำหรับ Key ใหม่

❻ ⚠️ คนที่มี Standard API Key เก่าควรทำอย่างไร

ควรตรวจหน้า API Keys และดู Column

Key Type

หาก Key แสดงว่า

Standard

ควรวางแผนย้ายไป Auth Key

เอกสารปัจจุบันของ Google ระบุว่ากำลังยุติการรองรับ Standard Key สำหรับ Gemini API ในช่วงเดือนกันยายน 2026

ดังนั้นอย่ารอจน Production Application เริ่มเกิด Authentication Error

Workflow ที่แนะนำคือ

ตรวจ Standard Key
↓
สร้าง Auth Key ใหม่
↓
เปลี่ยน Environment Variable
↓
Test
↓
Deploy
↓
ตรวจ Traffic
↓
ยกเลิก Key เก่า

❼ 🔄 วิธีเปลี่ยนจาก Standard Key เป็น Auth Key

ขั้นตอนคือ

❶ เปิด API Keys

เข้า Google AI Studio

❷ ตรวจ Key Type

ดูว่า Key ใดเป็น Standard

❸ กด Create API key

Key ใหม่จะถูกสร้างเป็น Auth Key ตามระบบปัจจุบัน

❹ Copy Key ใหม่

เก็บใน Secret Management ที่เหมาะสม

❺ เปลี่ยน Application

แก้

Environment Variable

หรือ Deployment Configuration ให้ใช้ Key ใหม่

❻ Test

ทดสอบ API Request

❼ Deploy

นำ Configuration ใหม่ไปใช้งาน

❽ ตรวจระบบ

ตรวจ Error และ Usage

❾ ยกเลิก Key เก่า

เมื่อแน่ใจว่า Traffic ทั้งหมดใช้ Key ใหม่แล้ว

ไม่ควรลบ Production Key เก่าก่อน Test Key ใหม่เรียบร้อย

❽ 📂 Gemini API Key ต้องอยู่ใน Google Cloud Project

API Key ทุกตัวจะสัมพันธ์กับ Google Cloud Project

Project ทำหน้าที่จัดการสิ่งต่าง ๆ เช่น

  • Billing
  • Collaborators
  • Permission
  • API
  • Usage
  • Quota

สามารถคิดเป็น

Google Cloud Project
├── Gemini API Key
├── Billing
├── IAM
└── Usage

ดังนั้นการจัด Project ให้เป็นระเบียบมีความสำคัญมากกว่าการสร้าง Key แบบสุ่มหลายรายการ

❾ 📁 ควรแยก Development กับ Production ไหม

สำหรับ Project จริงควรพิจารณาแยก Environment

ตัวอย่าง

Development
Staging
Production

ไม่ควรใช้ Key Production ตัวเดียวกับ

  • เครื่อง Developer
  • Code ทดลอง
  • Tutorial
  • Test Script

ทั้งหมด

การแยกช่วยด้าน

  • Security
  • Usage Tracking
  • Quota
  • Incident Response

ได้มากกว่า

❿ ☁️ มี Google Cloud Project อยู่แล้วทำอย่างไร

ถ้ามี Project ใน Google Cloud อยู่แล้ว แต่ไม่เห็นใน AI Studio ไม่ได้หมายความว่า Project หาย

Google AI Studio ปัจจุบันไม่ได้แสดง Google Cloud Project ทั้งหมดโดยอัตโนมัติ

ต้อง Import Project ที่ต้องการก่อน

ขั้นตอนคือ

❶ เปิด Dashboard

❷ เลือก Projects

❸ เลือก Import projects

❹ ค้นหา Project

เลือก Project ที่มีอยู่

❺ กด Import

จากนั้นกลับไปที่ API Keys เพื่อสร้าง Key ใน Project นั้น

📂 ทำไม Project ใน Google Cloud ไม่ขึ้นใน AI Studio

สาเหตุหนึ่งคือยังไม่ได้ Import Project

Flow คือ

Google Cloud Project
↓
Import into AI Studio
↓
AI Studio Projects
↓
API Keys

อย่ารีบสร้าง Project ใหม่เพียงเพราะไม่เห็น Project เดิม

อาจทำให้มี Project ซ้ำโดยไม่จำเป็น

🔐 Create API key กดไม่ได้เกิดจากอะไร

หากปุ่ม Create API key ใช้ไม่ได้ และระบบแจ้งลักษณะว่า

You do not have permission to create a key in this project

สาเหตุอาจมาจาก IAM Permission ของ Google Cloud Project

Google ระบุว่าการสร้าง Key ต้องมี Permission ที่เกี่ยวข้อง เช่น

resourcemanager.projects.get
apikeys.keys.create
serviceusage.services.enable
iam.serviceAccounts.create
iam.serviceAccountApiKeyBindings.create

ผู้ใช้ทั่วไปไม่จำเป็นต้องจำชื่อทั้งหมด แต่ควรเข้าใจว่าการสร้าง Auth Key ต้องมีสิทธิ์สร้าง Key และ Service Account ที่เกี่ยวข้อง

👤 Role ไหนสร้าง Key ได้

ตามเอกสาร Google AI Studio ปัจจุบัน

ผู้ที่มี Role เช่น

  • Owner
  • Editor

ใน Project มี Permission ครอบคลุมการจัดการส่วนสำคัญของ AI Studio มากกว่า Viewer

Viewer สามารถดูข้อมูลบางอย่างได้ แต่ไม่สามารถสร้าง แก้ หรือลบ API Key ได้เหมือน Role ที่มี Permission สูงกว่า

สำหรับองค์กรควรให้สิทธิ์เท่าที่จำเป็น ไม่ควรแจก Owner ทุกคนเพียงเพื่อสร้าง Key

🛡️ Principle of Least Privilege

หลักสำคัญคือ

ให้สิทธิ์เท่าที่จำเป็น

ตัวอย่าง Developer ต้องเพียงสร้างและใช้ Gemini API Key

ไม่ได้หมายความว่าจะต้องมีสิทธิ์

  • Billing Admin
  • Organization Admin
  • Project Owner

ทุกอย่าง

การลด Permission ช่วยลดผลกระทบหาก Account ถูกยึดหรือ Credential รั่ว

🔐 อย่าแชร์ Gemini API Key

API Key ควรถูกมองว่าเป็น Secret

ไม่ควรส่งผ่าน

  • Facebook
  • LINE Group
  • Public Chat
  • Blog
  • Screenshot
  • Public GitHub
  • Stack Overflow
  • HTML
  • Client-side JavaScript

ตัวอย่างที่ไม่ควรทำ

const GEMINI_API_KEY = "REAL_API_KEY";

โดยเฉพาะถ้า JavaScript นี้ถูกส่งไป Browser

🌐 ทำไมไม่ควรใส่ Key ใน Frontend

Browser Code สามารถถูกผู้ใช้ดูได้

เช่นผ่าน

  • View Source
  • Developer Tools
  • JavaScript Bundle
  • Network
  • Browser Extension

ดังนั้น Code

Browser
→ API Key
→ Gemini API

อาจทำให้ Key ถูกดึงออกไปใช้จากระบบอื่น

Architecture ที่ปลอดภัยกว่าคือ

Browser
↓
Your Server
↓
Secret API Key
↓
Gemini API

🔑 Environment Variable คือวิธีพื้นฐานที่ควรใช้

Google แนะนำให้ตั้ง Key เป็น Environment Variable

ชื่อที่ใช้ใน Getting Started คือ

GEMINI_API_KEY

ตัวอย่างแนวคิด

Operating System / Hosting
↓
GEMINI_API_KEY
↓
Application

แทนการเขียน Key ลง Source Code

🐧 ตั้ง API Key บน Linux/macOS

แนวคิดคือกำหนด Environment Variable

export GEMINI_API_KEY="YOUR_API_KEY"

จากนั้น Application ที่รองรับสามารถอ่านค่าจาก Environment

ควรใช้ Placeholder ใน Tutorial เสมอ

อย่าใส่ Key จริงใน Script ที่จะ Commit

🪟 Windows ทำอย่างไร

บน Windows สามารถตั้ง Environment Variable ด้วยวิธีของ

  • PowerShell
  • Command Prompt
  • Windows Environment Variables
  • IDE Configuration

ตาม Environment ที่ใช้

สิ่งสำคัญไม่ใช่คำสั่งเฉพาะ แต่คือให้ Application รับค่า

GEMINI_API_KEY

จาก Environment แทน Source Code

🐍 ใช้ Gemini API Key กับ Python

Google SDK ปัจจุบันใช้ Package

google-genai

ติดตั้ง

pip install -U google-genai

ตัวอย่างเริ่ม Client

from google import genai

client = genai.Client()

เมื่อกำหนด GEMINI_API_KEY ใน Environment ตามวิธีที่ SDK รองรับ Client สามารถใช้ Configuration นี้ได้โดยไม่ต้อง Hard-code Key ลงไฟล์ Python

🟨 ใช้กับ JavaScript

Google JavaScript SDK ปัจจุบันใช้ Package

@google/genai

ติดตั้ง

npm install @google/genai

การจัด API Key ควรอยู่ใน Server-side Environment

ไม่ควรทำ

Browser JavaScript
+
Secret Gemini API Key

โดยตรง

🌐 ใช้ REST API ได้ไหม

ได้

Gemini API สามารถเรียกผ่าน REST ได้ตาม API ที่รองรับ

แต่ Key ยังคงเป็น Credential ที่ต้องป้องกัน

หากใช้ curl สำหรับทดสอบในเครื่อง อย่า

  • บันทึก Key ลง Public Script
  • Paste Key ลง Tutorial
  • Capture Screenshot ที่เห็น Key
  • Commit Shell History หรือ Config โดยไม่ตรวจ

หลัง Test ควรตรวจว่าจะเก็บ Credential อย่างไรใน Deployment จริง

🆕 Interactions API กับ API Key

Getting Started ปัจจุบันของ Google แนะนำ Interactions API สำหรับ Project และ Application ใหม่ในหลาย Workflow

การ Authentication ยังคงต้องใช้ Credential เช่น Gemini API Key ตามวิธีที่ Googleรองรับ

ดังนั้น API Key ไม่ได้ผูกกับการเรียก generateContent แบบเก่าเพียงอย่างเดียว

ก่อนเขียน Application ใหม่ควรตรวจ Getting Started ปัจจุบันว่า API และ SDK ใดเป็น Recommendation ล่าสุด

⚠️ Tutorial เก่าอาจใช้ SDK คนละตัว

หากค้นจากอินเทอร์เน็ตอาจพบ Code เก่าที่ใช้ Package หรือ Import คนละแบบกับ SDK ปัจจุบัน

ก่อน Copy Code ควรตรวจ

  • Package
  • Import
  • Client
  • Model ID
  • API Method

จากเอกสาร Google ล่าสุด

API Key ถูกต้องอย่างเดียวไม่ได้ช่วยหาก Code ใช้ SDK ที่เลิกแนะนำแล้ว

🔒 Auth Key ปลอดภัยกว่า Standard Key อย่างไร

Auth Key ผูกกับ Google Cloud Service Account

ทำให้ Request มี Identity ที่ชัดกว่า Standard Key

Google ยังระบุถึงความสามารถด้านการบังคับใช้เมื่อ Key รั่วที่รวดเร็วขึ้นสำหรับ Auth Key

และ Key ใหม่ถูก Restrict สำหรับ Gemini API โดย Default

แต่ไม่ได้หมายความว่า

Auth Key
=
แชร์สาธารณะได้

Auth Key ยังคงต้องเก็บเป็น Secret เช่นเดิม

🚨 ถ้า API Key รั่วต้องทำอย่างไร

อย่ารอให้มีค่าใช้จ่ายหรือ Abuse ก่อน

ควรทำทันที

❶ หยุดใช้ Key

❷ สร้าง Key ใหม่

❸ เปลี่ยน Application Configuration

❹ Deploy

❺ Test

❻ Revoke/Delete Key เก่า

❼ ตรวจ Usage

ดูว่ามี Request ผิดปกติหรือไม่

❽ ตรวจ Git History

หากเคย Commit

❾ ตรวจ Log

ดูว่ามี Credential ถูกบันทึกไว้หรือไม่

Key ที่เปิดเผยควรถูกมองว่า Compromised

🐙 เผลอ Commit Key ลง GitHub ทำอย่างไร

เพียงลบ String ออกจาก Commit ล่าสุดไม่พอ

เพราะ Key อาจอยู่ใน

Git History

และ Bot อาจตรวจพบ Secret ได้รวดเร็ว

สิ่งสำคัญที่สุดคือ

Rotate Credential

ไม่ใช่เพียงซ่อนข้อความใน Repository

จากนั้นจึงจัดการ History และเพิ่มระบบป้องกันไม่ให้เกิดซ้ำ

📄 .env ใช้ได้ไหม

หลาย Project ใช้ไฟล์

.env

เพื่อจัด Environment Variable ใน Local Development

ตัวอย่าง

GEMINI_API_KEY=YOUR_API_KEY

แต่ .env ที่มี Secret ต้องอยู่ใน .gitignore หรือได้รับการจัดการให้เหมาะสม

อย่า Commit .env ที่มี Key จริงลง Public Repository

☁️ Production ควรใช้ Secret Manager ไหม

สำหรับระบบจริงควรพิจารณา Secret Management ของ Platform

ตัวอย่างแนวคิด

Secret Manager
↓
Runtime
↓
Application
↓
Gemini API

แทนการ Copy Key ใส่ Configuration File หลาย Server

ข้อดีคือ

  • จัด Permission ง่ายขึ้น
  • Rotate ง่ายขึ้น
  • ลด Secret ใน Source
  • Audit ได้ดีขึ้น

ตาม Platform ที่เลือก

🏗️ Google AI Studio Build mode จัด Key ให้อัตโนมัติ

ถ้าใช้ Build mode สร้าง App ใหม่ที่เรียก Gemini API

AI Studio ปัจจุบันสามารถตั้งค่า

GEMINI_API_KEY

เป็น Secret ฝั่ง Server ให้อัตโนมัติ

ไม่ต้อง Copy Key ไปฝังใน Frontend ด้วยตัวเอง

Gemini API Call ของ App จะทำจาก Server-side Code

ทำให้ Key ไม่ถูกเปิดเผยใน Browser

🔍 ดู Key ของ Build mode ที่ไหน

Google ระบุว่าสามารถดูและจัดการ Key ที่ Build mode ใช้ได้จาก

Settings
↓
Secrets

อย่างไรก็ตาม ไม่ควรเปิด Key เพียงเพื่อ Copy ไปใช้หลายที่โดยไม่มีเหตุผล

ควรสร้าง Credential Strategy ให้ชัดสำหรับแต่ละ Application

👥 แชร์ App แล้วคนอื่นเห็น API Key ไหม

สำหรับ Build mode ที่จัด Key เป็น Server-side Secret

Google ระบุว่า Key จะไม่ถูกส่งไป Client-side Code

ดังนั้นผู้ใช้ที่เปิด App ไม่ควรเห็น Key จาก Browser Source ตาม Architecture นี้

แต่ API Request ของผู้ใช้สามารถนับเข้า Usage ของ Project เจ้าของ App

จึงยังต้องควบคุม

  • Traffic
  • Rate Limit
  • Cost
  • Abuse

💰 API Key ผูกกับค่าใช้จ่ายอย่างไร

API Key เชื่อม Request กับ Project

Project อาจอยู่ใน

Free Tier

หรือ

Paid Tier

ถ้าเป็น Paid Project Request ที่คิดค่าบริการจะเข้าสู่ Billing ของ Project นั้น

จึงไม่ควรใช้ Paid Key กับ Public Demo แบบไม่มี Limit

💳 เปิด Billing จากหน้า API Keys ได้ไหม

ได้ตาม Workflow ปัจจุบัน

AI Studio มีตัวเลือก

Set up billing

ในส่วนที่เกี่ยวข้อง เช่น API Keys หรือ Projects

เมื่อเปิด Paid Tier จะต้องเชื่อม Cloud Billing ตามขั้นตอนที่ Google กำหนด

แต่การสร้าง API Key ไม่ได้หมายความว่าต้องเปิด Paid Tier เสมอไป เพราะ Gemini API มี Free Tier ตาม Model/Limit ที่รองรับ

📊 วิธีดูว่า Key กำลังถูกใช้หรือไม่

ควรติดตาม Gemini API Usage ผ่าน AI Studio

เช่น

Dashboard
↓
Usage

หลังเปลี่ยน Key หรือ Deploy Key ใหม่ ควรตรวจ

  • Request สำเร็จหรือไม่
  • Usage เพิ่มหรือไม่
  • Error เพิ่มหรือไม่

โดยเฉพาะช่วง Migration จาก Standard Key ไป Auth Key

⚡ API Key กับ Rate Limit

Rate Limit ของ Gemini API ไม่ได้ขึ้นกับ Key เพียงอย่างเดียว

โดยทั่วไปเกี่ยวข้องกับ

  • Project
  • Model
  • Usage Tier

ตามระบบปัจจุบัน

ดังนั้นการสร้าง Key เพิ่มหลายตัวใน Project เดียวไม่ใช่วิธีที่ควรใช้เพื่อหลบ Rate Limit

ถ้าต้องการเพิ่ม Capacity ควรดู Tier และ Quota ของ Project จริง

🚫 สร้าง API Key หลายอันเพื่อเพิ่ม Quota ได้ไหม

ไม่ควรใช้แนวทางนี้

Quota และ Rate Limit มีการจัดการระดับ Project/Model/Tier ตามข้อกำหนด

การสร้าง

Key A
Key B
Key C

ไม่ได้หมายความว่าได้ Quota เพิ่มเป็น 3 เท่าโดยอัตโนมัติ

ควรจัด Key ตาม

  • App
  • Environment
  • Security

มากกว่าการใช้เพื่อหลบข้อจำกัด

🔍 AI Studio แสดง API Key ได้ทั้งหมดไหม

มีข้อจำกัด

Google ระบุว่า API Keys และ Projects Page ใน AI Studio แสดงจำนวน Key และ Project ได้สูงสุดตาม Limit ของ Interface

ปัจจุบันหน้าเหล่านี้สามารถแสดงได้สูงสุด

  • 100 API Keys
  • 50 Projects

และ Key ที่แสดงจะเป็น Key ที่ตรงกับประเภท/Restriction ที่ AI Studio รองรับ

สำหรับการจัดการขั้นสูงอาจต้องใช้ Google Cloud Console

📁 สร้าง Project ใน AI Studio ได้กี่ Project

Google ระบุข้อจำกัดว่าจาก AI Studio Projects Page สามารถสร้าง Project ได้สูงสุด

10 Projects at a time

สำหรับระบบองค์กรขนาดใหญ่ควรวาง Project Structure ผ่าน Google Cloud อย่างเหมาะสม ไม่ควรใช้ AI Studio เป็นเครื่องมือ Project Management เพียงตัวเดียว

🔒 Unrestricted Standard Key คืออะไร

Key Standard รุ่นเก่าบางตัวอาจแสดงสถานะ

Unrestricted

Google ปัจจุบันเพิ่มมาตรการด้าน Security และ Gemini API ปฏิเสธ Standard Key ที่ไม่มี Restriction ตามเงื่อนไขใหม่

หากยังมี Key ประเภทนี้ ควร

  • เพิ่ม Restriction ตามแนวทาง Google
  • หรือ Migration ไป Auth Key

โดย Auth Key ใหม่เป็นทางเลือกที่ตรงกับ Direction ปัจจุบันมากกว่า

⛔ Dormant Key อาจถูก Block

Google ระบุว่าตั้งแต่วันที่ 7 พฤษภาคม 2026 มีมาตรการ Block Unrestricted API Key ที่ไม่ได้ใช้งานเป็นระยะเวลานาน

Key ลักษณะนี้อาจแสดง Tag

Blocked

หากพบ Key เก่าที่ถูก Block ควรสร้าง Key ใหม่หรือใช้ Key ที่มี Restriction เหมาะสมแทน

อย่าพยายามพึ่ง Key เก่าที่ไม่ได้ดูแลมานาน

🔐 API Key กับ OAuth ต่างกันอย่างไร

API Key เป็นวิธีเริ่ม Authentication กับ Gemini API ที่ง่ายมาก

แต่ Google ยังรองรับ OAuth สำหรับกรณีที่ต้องการ Access Control ที่เข้มงวดขึ้นตาม Architecture

Getting Started ของ OAuth ปัจจุบันยังระบุว่า API Key เป็นวิธีที่ง่ายที่สุดในการเริ่มต้น Gemini API

ส่วนระบบ Production ที่มี Requirement ด้าน Identity/Authorization สูง ควรประเมิน Credential Type ให้เหมาะสม

🧠 API Key ไม่ใช่ User Login

อย่าสับสน

Gemini API Key

กับ

User Authentication

API Key บอกว่า Application/Project มี Credential ในการเรียก API

ไม่ได้ยืนยันว่า

ผู้ใช้คนนี้คือใคร

หาก App มี User Account ยังต้องมี Authentication และ Authorization ของ Application แยกต่างหาก

🔐 ตัวอย่าง Architecture ที่ถูกกว่า

User
↓
Login
↓
Your Backend
↓
Check Permission
↓
GEMINI_API_KEY
↓
Gemini API

ไม่ใช่

User
↓
รับ GEMINI_API_KEY
↓
เรียก Gemini เอง

โดยเฉพาะ Production SaaS

🧪 วิธีทดสอบว่า API Key ใช้งานได้

หลังตั้ง Environment Variable และ SDK แล้ว ให้สร้าง Request ที่ง่ายที่สุดก่อน

Workflow

API Key
↓
SDK Client
↓
Simple Prompt
↓
Gemini API
↓
Response

อย่าเริ่มจาก

  • File Upload
  • Function Calling
  • Search
  • Streaming
  • Agent

พร้อมกัน

หาก Request ง่ายยังไม่ผ่าน จะ Debug ได้ง่ายกว่า

❌ API Key ใช้ไม่ได้เกิดจากอะไร

สาเหตุที่พบได้ เช่น

Key ผิด

Copy ไม่ครบ

Environment Variable ไม่ถูก Load

Application อ่านค่าไม่ได้

Project Permission

ไม่มีสิทธิ์

API Configuration

Project ยังไม่พร้อม

Key เก่า

Standard/Unrestricted Key มีปัญหาตาม Security Requirement ใหม่

Region/Account

ไม่ตรงข้อกำหนด

Billing/Tier

Model หรือ Feature ต้องการ Tier ที่แตกต่าง

Rate Limit

Request มากเกินไป

ควรอ่าน Error Code ก่อนสร้าง Key ใหม่

🚫 อย่าแก้ทุก Error ด้วยการสร้าง Key ใหม่

ตัวอย่าง

429 Too Many Requests

ไม่ใช่ปัญหาว่า Key เสีย

แต่เกี่ยวข้องกับ Rate Limit หรือ Quota

หรือ

400 Bad Request

อาจเป็น Request Format

ดังนั้นต้องอ่าน Error ก่อน

หัวข้อ Error 400, 403, 404 และ 429 จะมีบทความเฉพาะในชุดนี้

🔁 ควร Rotate API Key เมื่อไร

ควรพิจารณา Rotate เมื่อ

  • Key รั่ว
  • Employee เปลี่ยนหน้าที่
  • Project Security Policy กำหนด
  • Credential ถูกแชร์ผิด
  • GitHub Secret Exposure
  • Incident
  • Key เก่ามากและไม่ทราบ Usage

การ Rotate ควรมีขั้นตอน

Create New
↓
Deploy
↓
Test
↓
Switch Traffic
↓
Revoke Old

เพื่อลด Downtime

🏷️ ตั้งชื่อ Key ให้เข้าใจง่าย

หากระบบรองรับการตั้งชื่อ ควรใช้ Convention

ตัวอย่าง

comsiam-dev
comsiam-staging
comsiam-production

ดีกว่า

Key 1
Key 2
Key 3

เมื่อเกิด Incident จะรู้ได้ทันทีว่า Key ใดเกี่ยวข้องกับ Environment ไหน

นี่คือหนึ่งในแนวทางจัด Credential ที่ comsiam สามารถนำไปใช้กับ Project จริงได้

📋 Checklist หลังสร้าง Gemini API Key

✅ Key Type

ตรวจว่าเป็น Auth Key ตามระบบใหม่

✅ Project

อยู่ Project ถูกต้อง

✅ Environment

Development หรือ Production

✅ Storage

เก็บเป็น Secret

✅ Git

ไม่มี Key จริงใน Repository

✅ Frontend

ไม่มี Secret อยู่ใน Browser

✅ Usage

ตรวจ Dashboard

✅ Billing

รู้ว่า Project เป็น Free หรือ Paid

✅ Test

Request ใช้งานได้

✅ Old Key

ยกเลิก Key ที่ไม่ใช้เมื่อเหมาะสม

🚫 10 ข้อผิดพลาดเมื่อสร้าง Gemini API Key

❶ สร้าง Key ใหม่โดยไม่ดูก่อนว่ามีอยู่แล้ว

Key เยอะเกินจำเป็น

❷ เลือก Project ผิด

Usage ไปผิด Environment

❸ ใช้ Standard Key เก่าต่อโดยไม่ตรวจ

เสี่ยง Service Interruption จากการเปลี่ยนระบบ Key

❹ ใส่ Key ใน Source Code

Secret รั่วได้

❺ ใส่ Key ใน Frontend

ผู้ใช้ดึง Key ได้

❻ Commit .env

Key เข้า Git History

❼ แชร์ Screenshot

Key ปรากฏในภาพ

❽ ใช้ Production Key ทดสอบทุกอย่าง

แยก Usage ยาก

❾ สร้าง Key เพิ่มเพื่อหวังเพิ่ม Quota

ไม่ใช่วิธีจัดการ Rate Limit

❿ Key รั่วแล้วแค่ลบจาก Code

ต้อง Rotate Credential ด้วย

🪜 Workflow สร้าง Gemini API Key ที่แนะนำ

ขั้นตอนที่เหมาะสำหรับ Project จริงคือ

❶ เลือก Google Account

ใช้บัญชีที่ถูกต้อง

❷ เข้า AI Studio

เปิด Dashboard

❸ ตรวจ Projects

เลือกหรือ Import Project

❹ ตรวจ API Keys

ดูว่ามี Key อยู่แล้วหรือไม่

❺ Create API key

สร้างเมื่อจำเป็น

❻ ตรวจ Key Type

ใช้ Auth Key รุ่นใหม่

❼ Copy

เก็บในที่ปลอดภัย

❽ Environment Variable

ใช้ GEMINI_API_KEY

❾ Test

ทำ Request ง่ายก่อน

❿ ตรวจ Usage

ยืนยันว่า Project ถูก

⓫ แยก Environment

Dev/Staging/Production ตามความเหมาะสม

⓬ Secret Management

ใช้ระบบที่เหมาะกับ Hosting

⓭ Deploy

ไม่ฝัง Key ใน Client

⓮ Monitor

ตรวจ Usage และ Error

⓯ Rotate

เมื่อมีเหตุผลด้าน Security

Workflow นี้ช่วยลดทั้งปัญหา Key รั่ว Project สับสน และค่าใช้จ่ายที่เกิดกับ Environment ผิด

💡 10 ข้อควรจำเกี่ยวกับ Gemini API Key

❶ API Key คือ Secret

อย่าแชร์

❷ ผู้ใช้ใหม่อาจมี Key อยู่แล้ว

ตรวจก่อนสร้าง

❸ Key ใหม่เป็น Auth Key

ตามระบบปัจจุบัน

❹ Standard Key กำลังถูกยกเลิกสำหรับ Gemini API

ควร Migration

❺ Key อยู่ภายใต้ Project

Project สำคัญกับ Billing/Quota

❻ ใช้ Environment Variable

แทน Hard-code

❼ Frontend ไม่ใช่ที่เก็บ Secret

ใช้ Backend

❽ Build mode จัด Key ฝั่ง Server ให้ได้

สะดวกสำหรับ App ใหม่

❾ Key เพิ่มไม่ได้แปลว่า Quota เพิ่ม

ดู Tier/Project

❿ Key รั่วต้อง Rotate

ลบจาก Codeอย่างเดียวไม่พอ

❓ คำถามที่พบบ่อย

สร้าง Gemini API Key ที่ไหน

สามารถสร้างและจัดการ Gemini API Key ผ่าน Google AI Studio ในหน้า API Keys ของ Dashboard

ผู้ใช้ใหม่ต้องสร้าง API Key เองไหม

ไม่เสมอไป Google AI Studio ปัจจุบันสามารถสร้าง Default Google Cloud Project และ API Key ให้ผู้ใช้ใหม่โดยอัตโนมัติหลังยอมรับเงื่อนไข

API Key ใหม่เป็น Standard Key หรือ Auth Key

API Key ใหม่ที่สร้างใน Google AI Studio ปัจจุบันถูกสร้างเป็น Authorization Key หรือ Auth Key โดยอัตโนมัติ

Gemini API Key ฟรีไหม

การสร้าง Key ไม่ได้มีค่าใช้จ่ายในตัวมันเอง แต่ Request ผ่าน Key จะอยู่ภายใต้ Free Tier หรือ Paid Tier ของ Project และ Model ที่ใช้

ควรใส่ Gemini API Key ใน JavaScript หน้าเว็บไหม

ไม่ควรใส่ Secret API Key ลง Client-side JavaScript สำหรับ Production ควรเรียกผ่าน Server-side Code หรือใช้ Secret Management ที่เหมาะสม

ถ้ามี Standard API Key เก่าควรทำอย่างไร

ควรตรวจ Key Type ใน AI Studio และ Migration ไป Auth Key เนื่องจาก Google กำลังยุติการรองรับ Standard Key สำหรับ Gemini API ตามนโยบาย Authentication รุ่นใหม่

🎯 สรุป

วิธีสร้าง Gemini API Key ใน Google AI Studio ปัจจุบันง่ายมาก โดยเข้า Dashboard → API Keys → Create API key → เลือก Project → สร้างและ Copy Key

ผู้ใช้ใหม่อาจไม่จำเป็นต้องสร้างเอง เพราะ AI Studio สามารถสร้าง Default Project และ API Key เริ่มต้นให้อัตโนมัติ

การเปลี่ยนแปลงสำคัญคือ API Key ใหม่ใน AI Studio ปัจจุบันเป็น Authorization Key หรือ Auth Key ซึ่งผูกกับ Google Cloud Service Account และถูกออกแบบให้มี Security และ Access Control ที่ดีกว่า Standard Key รุ่นเดิม

ผู้ที่ยังมี Standard API Key ควรตรวจและ Migration ไป Auth Key เพราะ Google กำลังเปลี่ยน Gemini API ออกจาก Standard Key ในช่วงเดือนกันยายน 2026

หลังได้ Key แล้วควรตั้งเป็น GEMINI_API_KEY ใน Environment หรือ Secret Management และห้ามฝัง Key จริงลง Source Code, Public Repository หรือ Client-side JavaScript

หากสร้าง App ผ่าน AI Studio Build mode ระบบสามารถตั้ง GEMINI_API_KEY เป็น Server-side Secret ให้อัตโนมัติ ทำให้ไม่ต้องส่ง Key ไปยัง Browser

แนวทางของ comsiam คือสร้าง Key เท่าที่จำเป็น แยก Development/Production ให้ชัด เก็บ Key เป็น Secret ตรวจ Usage เป็นประจำ และ Rotate ทันทีหากสงสัยว่า Credential ถูกเปิดเผย