> ## Documentation Index
> Fetch the complete documentation index at: https://docs.raze.bot/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Three ways to send the key. Only /health and /v1/openapi.yaml are public.

Every route except `/health` and `/v1/openapi.yaml` needs a key. The API reads it from the first of:

1. Header `x-api-key: <key>`
2. Header `Authorization: Bearer <key>`
3. Query `?apiKey=<key>` (`?api_key=` works too)

A missing or unknown key answers **401**:

```json theme={null}
{ "error": { "code": "unauthorized", "message": "missing or unknown API key (send it as x-api-key)" } }
```

```bash theme={null}
curl -H "x-api-key: $KEY" https://api.raze.bot/v1/chains
curl -H "Authorization: Bearer $KEY" https://api.raze.bot/v1/chains
```

## WebSocket and SSE

Browsers cannot set headers on a `WebSocket` or an `EventSource`, so both take the key in the URL. The WebSocket checks it before the upgrade: a bad key never becomes a socket.

```javascript theme={null}
const ws = new WebSocket(`wss://api.raze.bot/v1/ws?apiKey=${KEY}`); // or wss://ws.raze.bot/?apiKey=…
const es = new EventSource(`https://api.raze.bot/v1/stream/trades?chain=sol&token=${mint}&apiKey=${KEY}`);
```

Server-side clients (Node, Python, Go) can send `x-api-key` on the upgrade request instead.

## Playground

The interactive playground in these docs sends `x-api-key`. Paste the raw key.

## Key hygiene

* Keep keys on your server, in environment variables. A key in a browser bundle or a page URL is a public key.
* For a web app, proxy REST and the WebSocket through your backend and add the key there.
* Limits are per key: see [Rate limits](/get-started/rate-limits).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.