Authentication

Authentication summary

EasyAPI authenticates API requests with a bearer token. Send Authorization: Bearer YOUR_API_KEY on every request; a missing, invalid, or disabled key causes authentication to fail.

Key facts

  • Every API request should include the Authorization header.
  • Disable or rotate a key immediately if it is exposed.
  • Use separate tokens for different applications or environments to limit access and track usage.

API authentication FAQ

How do I format the EasyAPI Authorization header?
Use Authorization: Bearer YOUR_API_KEY and replace YOUR_API_KEY with an active token created in the console.
Why does an EasyAPI request return 401?
Typical causes are a missing token, an invalid or disabled token, or an incorrectly formatted Bearer header.

Authentication

Authenticate EasyAPI requests with a Bearer token in the Authorization header: header format, API key security best practices and 401 / 403 error responses.

Every API request must include a Bearer token in the Authorization header.

Header format

Authorization: Bearer YOUR_API_KEY

Security recommendations

  1. Never hard-code API keys in client apps (browsers, mobile apps)
  2. Use separate tokens for each environment (development / staging / production)
  3. Rotate keys regularly and revoke leaked tokens in the console

Error responses

HTTP statusError codeDescription
401invalid_api_keyMissing or invalid API key
403forbiddenThe token is not allowed to access this resource

See Error Codes and Status Codes for details.