Skip to main content
Every route except /health and /v1/openapi.yaml needs a key. The API reads it from the first of:
  1. Header x-api-key: <key>
  2. Header Authorization: Bearer <key>
  3. Query ?apiKey=<key> (?api_key= works too)
A missing or unknown key answers 401:

WebSocket and SSE

Browsers cannot set headers on a WebSocket or an EventSource, so both take the key in the URL. The WebSocket checks it before the upgrade: a bad key never becomes a socket.
Server-side clients (Node, Python, Go) can send x-api-key on the upgrade request instead.

Playground

The interactive playground in these docs sends x-api-key. Paste the raw key.

Key hygiene

  • Keep keys on your server, in environment variables. A key in a browser bundle or a page URL is a public key.
  • For a web app, proxy REST and the WebSocket through your backend and add the key there.
  • Limits are per key: see Rate limits.