x-api-key request header.
Create and manage keys
Open API access while signed in. You can create, reveal, copy, rename, and revoke keys there. Use a separate named key for every integration so usage can be attributed and one integration can be rotated without interrupting another.Never place an API key in browser code, a Git repository, screenshots, analytics events, or logs. Load it at runtime from your server’s secret manager or environment.
Keys belong to the signed-in account. They can read only that account’s searches and enrichment jobs, and share the account’s subscription, credits, concurrency allowance, and 1,000-request rolling rate limit.
Authentication errors
Revocation takes effect on the next request. Treat an exposed key as compromised: revoke it, issue a replacement, update the integration, and verify recent activity in API analytics.
