Skip to main content
Every request to the Hypedexer API is authenticated with an API key. You create and revoke keys yourself in the console at app.hypedexer.com, see Generate API key.

Sending the key

The examples in this documentation use the X-API-Key header:
The API accepts the key in three places. They are equivalent, pick the one your client makes easiest.
Browsers cannot set custom headers on a WebSocket handshake. From a browser, connect with wss://api.hypedexer.com/ws?api_key=<key>. Prefer a header everywhere else: query strings end up in access logs and browser history.
The same key works for the hosted MCP server.

When authentication fails

Both cases return HTTP 401 with a plain-text body. A WebSocket handshake without a valid key is refused with 401 before the connection opens. Failed requests are not charged. The full list of error codes is in Errors.

Keeping keys safe

  • Keep keys out of client-side code and public repositories. Use an environment variable or your secret manager.
  • Create one key per service or environment, so that you can revoke one without touching the others.
  • Revoking a key in the console stops every request that uses it.

Free tier

Every account can call the API for free within a monthly credit allowance, enough to test an integration end to end. When the allowance is used up, upgrade or wait for the reset (every 30 days from plan activation). Plans, credits and limits are in Rate Limits & Pricing.

Need help?

Telegram

Discord

Email

Twitter