Browse documentation
Docs / Start
Authentication
Every public API request requires a personal key in the HTTP Authorization header.
Bearer header
Send the key on every call. Query-string keys are not accepted because URLs are commonly stored in logs and browser history.
Authorization: ******Keep keys secure
- Store keys in environment variables or a managed secret store.
- Do not commit keys, embed them in client-side JavaScript, or share screenshots containing them.
- Use separate keys for separate applications so one integration can be revoked independently.
- Revoke and replace a key immediately if it is exposed.
Key and credit errors
| Code | Meaning | Action |
|---|---|---|
| MISSING_KEY | No bearer token was supplied. | Add the Authorization header. |
| INVALID_KEY | The key is unknown, revoked or malformed. | Check or rotate the key. |
| INSUFFICIENT_CREDITS | The monthly credit pool is exhausted. | Wait for reset or request a higher tier. |
