---
title: Authentication
description: Send your SteamSets API key as a bearer token, and keep it out of client-side code.
sidebar:
  icon: key-round
  order: 2
---

The API uses bearer tokens. Send your API key in the `Authorization` header of each request:

```http
Authorization: Bearer your-key
```

A request without a valid key gets a `401 Unauthorized` response.

## Get a key

Create a developer app in [Settings, API keys](https://steamsets.com/settings/api-keys) on steamsets.com. Each developer app has one API key. SteamSets shows the key one time only, when you create it or generate a new one.

## Keep the key secret

Your key identifies your developer app, and all requests with it count toward the limits of that app.

- Keep the key on a server. Do not put it in browser code, a mobile app, or a public repository.
- Read the key from an environment variable or a secret store.
- If a key leaks, generate a new key in [Settings, API keys](https://steamsets.com/settings/api-keys).

:::note
Some endpoints in the live API are for the steamsets.com website only and need a browser session. This reference does not show them, because an API key cannot call them.
:::

## Try it in the reference

Each page in the [API reference](/reference) has a **Try it** panel. Paste your key into the panel to send real requests from your browser. The key stays in memory and goes only to `api.steamsets.com`. Select **Remember on this device** to keep it in local storage for your next visit.
