Skip to content
SteamSets
Esc
↑↓navigate↵open⌘Jpreview
On this page

Authentication

Send your SteamSets API key as a bearer token, and keep it out of client-side code.

The API uses bearer tokens. Send your API key in the Authorization header of each request:

Authorization: Bearer your-key

A request without a valid key gets a 401 Unauthorized response.

Get a key

Create a developer app in Settings, API keys on steamsets.com. Each developer app has one API key. SteamSets shows the key one time only, when you create it or generate a new one.

Keep the key secret

Your key identifies your developer app, and all requests with it count toward the limits of that app.

  • Keep the key on a server. Do not put it in browser code, a mobile app, or a public repository.
  • Read the key from an environment variable or a secret store.
  • If a key leaks, generate a new key in Settings, API keys.

Try it in the reference

Each page in the API reference has a Try it panel. Paste your key into the panel to send real requests from your browser. The key stays in memory and goes only to api.steamsets.com. Select Remember on this device to keep it in local storage for your next visit.