Getting startedAuthentication

Authentication

Every request carries your key in one header. There are no tokens to refresh and no sessions to keep alive.

Send your key

Add the header Authorization: Bearer sk_live_… to every request (X-API-Key: sk_live_… works too). Requests without a valid key get a 401 response.

Keep it safe

  • Store the key in an environment variable or your secret manager, never in code you commit.
  • Call the API from your server or a serverless function, then send your own visitors only what they need.
  • If a key leaks, rotate it in your account. The old key stops working at once.

What a key can reach

A key answers for the sports and the Insights level in your plan. A request for another sport returns 403 with the code FORBIDDEN, and Insights on a Data plan returns FEATURE_NOT_IN_PLAN, so you can show a clear message instead of an empty page.

AI agents that pay per call do not need a key. See AI agents.