Sending the key
Pass it in either header:Verify
Handling
- Treat the key as a secret. Store it in your secrets manager, never in source control or client-side code.
- Keys are prefixed
rec_sk_so leaked keys are flagged by secret scanners. - All traffic is TLS 1.2+. Requests over plain HTTP are rejected.
401 Unauthorized.