/health and /v1/openapi.yaml needs a key. The API reads it from the first of:
- Header
x-api-key: <key> - Header
Authorization: Bearer <key> - Query
?apiKey=<key>(?api_key=works too)
WebSocket and SSE
Browsers cannot set headers on aWebSocket or an EventSource, so both take the key in the URL. The WebSocket checks it before the upgrade: a bad key never becomes a socket.
x-api-key on the upgrade request instead.
Playground
The interactive playground in these docs sendsx-api-key. Paste the raw key.
Key hygiene
- Keep keys on your server, in environment variables. A key in a browser bundle or a page URL is a public key.
- For a web app, proxy REST and the WebSocket through your backend and add the key there.
- Limits are per key: see Rate limits.