If your API key is missing or invalid, you'll receive a 401 Unauthenticated response:
{
"message": "Unauthenticated"
}
Security Best Practices
Never commit your API key to version control
Store API keys in environment variables or secure config files
Rotate your API keys regularly
Use different API keys for dev, staging, and production
Revoke compromised keys immediately and generate new ones
Keep Your API Key Secret
Never expose your API key in client-side code or public repositories. If you suspect your key has been compromised, revoke it immediately from your dashboard.