Using APIs

API keys

Create, view, rotate and protect the key that authenticates your calls.

Your API key is how the gateway knows a request comes from you. Treat it like a password.

One key for everything

A single key works for every API you're subscribed to. You don't need a separate key per API. The gateway checks your key, then checks that you have an active subscription to the API you're calling.

Creating a key

Open Console → API Keys and click Create key. Give it a name that tells you where it's used (for example "Production server" or "Mobile app"). You can create several keys, for example one per app, so you can revoke one without affecting the others.

Viewing a key

Keys are hidden by default. Click the eye icon to reveal a key, then copy it.

Using a key

Send it in the X-API-Key header on every request:

curl "https://countries-info.p.apihiver.com/v1/countries/IN" \
  -H "X-API-Key: YOUR_API_KEY"

Rotating and deleting keys

To replace a key, create a new one, update your apps to use it, then delete the old one. A deleted key stops working immediately; any request that uses it is rejected with 401 INVALID_API_KEY.

Keeping keys safe

  • Never put a key in front-end code (a website's JavaScript or a mobile app) where users can read it. Call the API from your own server instead.
  • Don't commit keys to Git. Load them from environment variables or a secrets manager.
  • If a key might have leaked, delete it and create a new one straight away.

Something unclear or missing? Email [email protected].