Sending the key
The examples in this documentation use theX-API-Key header:
Browsers cannot set custom headers on a WebSocket handshake. From a browser, connect with
wss://api.hypedexer.com/ws?api_key=<key>. Prefer a header everywhere else: query strings end up in access logs and browser history.When authentication fails
Both cases return HTTP401 with a plain-text body. A WebSocket handshake without a valid key is refused with 401 before the connection opens.
Failed requests are not charged. The full list of error codes is in Errors.
Keeping keys safe
- Keep keys out of client-side code and public repositories. Use an environment variable or your secret manager.
- Create one key per service or environment, so that you can revoke one without touching the others.
- Revoking a key in the console stops every request that uses it.