/v1 must carry your API key in the Authorization header, as a bearer token:
REST requests
Send the header on every request:Bearer is case-insensitive. The key itself is case-sensitive.
Stream handshake
The WebSocket at/v1/stream takes the same header on its opening HTTP request. The server checks the key before the upgrade, so a client without a valid key never gets a socket.
When authentication fails
A missing, malformed, unknown, revoked or expired key gets the same response:401: check that the key is set, sent in the right header, and not expired or revoked.
A
503 SERVICE_UNAVAILABLE means the server could not check your key at that moment. It says nothing about your key. Retry with backoff and keep using the same key.Keys belong on your backend
Call the API only from servers you control.- Browsers: the API sends no CORS headers, so browser requests fail. A browser’s WebSocket API also cannot set the
Authorizationheader. - Mobile and desktop apps: anyone can extract a key from a shipped app.
Endpoints that need no key
GET https://{{API_HOST}}/openapi.json serves the OpenAPI document without a key, so you can generate a client before you have one.