Authentication
Send credentials as bearer tokens over HTTPS.
Authorization: Bearer YOUR_API_KEY
Safe handling#
- Store keys in an approved secrets manager.
- Never expose them in client-side code, URLs, or logs.
- Use separate test and production credentials.
- Rotate immediately after suspected disclosure.
A missing credential returns 401. Insufficient permission returns 403. Out-of-scope resources may return 404 to avoid information disclosure.
Was this useful?