ドキュメント · はじめに

認証

Every request is authenticated with an API key. Keys are created and managed in the console.

本文は現在英語版のみ提供しています。

OpenAI format

Send the key as a Bearer token in the Authorization header:

Authorization: Bearer YOUR_API_KEY

Anthropic format

For /v1/messages, use the x-api-key and anthropic-version headers, as with Anthropic (Authorization: Bearer also works):

x-api-key: YOUR_API_KEY
anthropic-version: 2023-06-01

Keeping keys safe

  • Use API keys on the server only — never in browsers, mini-programs or mobile apps. Proxy front-end calls through your own backend.
  • Store keys in environment variables or a secrets manager, never in your repository.
  • Create separate keys per project and environment so usage is tracked separately and each can be revoked on its own.
  • If a key may have leaked, delete it in the console right away and create a new one.

Authentication failures return 401. See Error codes and Troubleshooting.