When the API was first released I think they were 6 characters so any older players who haven't reset their keys will still be 6, otherwise everyone should be 8.
But, checking length is pointless. If someone enters 8 random characters that end up not being a key your script will fail anyway, so you might as well do it the right way...
The API has built-in error codes you can use. If somebody enters a bad key the API will return:
{ "error": { "code": 2, "error": "Incorrect Key" } }
So you can always just check for that and abort the script with the Torn error message or a personalized error message.
All the error codes are listed at the bottom of the page on
http://api.torn.com/ with the exception of error code number 9, which appears when Torn disabled the API globally for some reason or the API is not available - such as updates, server reboot, etc.