Authentication
API keys and the Authorization header.
Authenticate every request
Every request is authenticated with an API key sent as a bearer token in the Authorization header.
curl https://api.outerview.ai/v1/stream \
-X POST \
-H "Authorization: Bearer $OUTERVIEW_API_KEY" \
-H "Content-Type: application/json" \
-d '{"query": "potholes"}'Create a key
Create a key in the developer console. Name it after the environment and owner (for example prod-maps-team) so usage is easy to trace.
Scope
Each key is scoped to one environment and one service. Create separate keys for development, staging, and production, and never share one key across environments.
Keep keys safe
Store keys in environment variables, for example OUTERVIEW_API_KEY.
Never commit keys to source control.
Never expose a key in browser or other client-side code. Call Stream from your server and pass only the results to the client.
If a key is exposed, revoke it and create a new one.
A missing, malformed, or revoked key returns 401. See Limits and Errors.