Authentication summary
EasyAPI authenticates API requests with a bearer token. Send Authorization: Bearer YOUR_API_KEY on every request; a missing, invalid, or disabled key causes authentication to fail.
Key facts
- Every API request should include the Authorization header.
- Disable or rotate a key immediately if it is exposed.
- Use separate tokens for different applications or environments to limit access and track usage.
API authentication FAQ
- How do I format the EasyAPI Authorization header?
- Use Authorization: Bearer YOUR_API_KEY and replace YOUR_API_KEY with an active token created in the console.
- Why does an EasyAPI request return 401?
- Typical causes are a missing token, an invalid or disabled token, or an incorrectly formatted Bearer header.
Authentication
Authenticate EasyAPI requests with a Bearer token in the Authorization header: header format, API key security best practices and 401 / 403 error responses.
Every API request must include a Bearer token in the Authorization header.
Header format
Authorization: Bearer YOUR_API_KEY
Security recommendations
- Never hard-code API keys in client apps (browsers, mobile apps)
- Use separate tokens for each environment (development / staging / production)
- Rotate keys regularly and revoke leaked tokens in the console
Error responses
| HTTP status | Error code | Description |
|---|---|---|
401 | invalid_api_key | Missing or invalid API key |
403 | forbidden | The token is not allowed to access this resource |
See Error Codes and Status Codes for details.