Authentication

API keys and the Authorization header.

Authenticate every request

Every request is authenticated with an API key sent as a bearer token in the Authorization header.

bash
curl https://api.outerview.ai/v1/stream \
  -X POST \
  -H "Authorization: Bearer $OUTERVIEW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"query": "potholes"}'

Create a key

Create a key in the developer console. Name it after the environment and owner (for example prod-maps-team) so usage is easy to trace.

Open the API keys page

Scope

Each key is scoped to one environment and one service. Create separate keys for development, staging, and production, and never share one key across environments.

Keep keys safe

Store keys in environment variables, for example OUTERVIEW_API_KEY.

Never commit keys to source control.

Never expose a key in browser or other client-side code. Call Stream from your server and pass only the results to the client.

If a key is exposed, revoke it and create a new one.

A missing, malformed, or revoked key returns 401. See Limits and Errors.