API Key
Include your API key in theX-API-Key header with every request:
Key Format
Security
Environment Variables
Never hardcode keys in source code
Server-Side Only
Never expose keys in client-side code
Rotate Regularly
Generate new keys periodically
Revoke Immediately
Delete compromised keys instantly
Example Setup
Rate Limit Headers
Every response includes rate limit information:Error Responses
| Status | Code | Description |
|---|---|---|
| 401 | UNAUTHORIZED | Missing or invalid API key |
| 429 | RATE_LIMIT_EXCEEDED | Too many requests |
