← Docs/Authentication & API Keys

Authentication & API Keys

Authentication

All API requests require authentication via the API Key in the HTTP Header.

OpenAI-Compatible Format (Recommended)

Authorization: Bearer utk_xxxxxxxx

Key Only (No Bearer)

Authorization: utk_xxxxxxxx

API Key Format

UnionToken API Key format: utk_ prefix + 64 hexadecimal characters:

utk_a1b2c3d4e5f6...

Security Best Practices

  • Never hardcode API Keys in client-side code
  • Use environment variables to manage Keys
  • Create different Keys for dev/production environments
  • Rotate Keys regularly and revoke unused ones
  • Never expose Keys in public repositories

Key Permissions

Current API Keys have full permissions. Fine-grained permission control is planned.