Authentication & API Keys
Authentication
All API requests require authentication via the API Key in the HTTP Header.
OpenAI-Compatible Format (Recommended)
Authorization: Bearer utk_xxxxxxxxKey Only (No Bearer)
Authorization: utk_xxxxxxxxAPI Key Format
UnionToken API Key format: utk_ prefix + 64 hexadecimal characters:
utk_a1b2c3d4e5f6...Security Best Practices
- Never hardcode API Keys in client-side code
- Use environment variables to manage Keys
- Create different Keys for dev/production environments
- Rotate Keys regularly and revoke unused ones
- Never expose Keys in public repositories
Key Permissions
Current API Keys have full permissions. Fine-grained permission control is planned.