Get started
Authentication
Every request needs an API key, sent as a bearer token.
Send your key
header
Authorization: Bearer sr_live_...Create keys on the API keys page. We only store a hash, so the full key is shown once.
Good to know
- Keep keys on your server. Anyone with a key can spend your balance.
- Use a separate key for each app or environment, so you can turn one off without affecting the rest.
- Revoked keys are rejected with
401 unauthorizedand can't be restored. - Disabled keys are rejected too, and work again as soon as you enable them.
- Being signed in to the console doesn't authorize API calls. Always send a key.
- Each key has a request limit per minute. See Limits.