Authentication
How to authenticate API requests to Pofano.
All API requests to Pofano require authentication. The primary authentication method is a Bearer token passed in the Authorization header.
Bearer Token#
Include your API key in the Authorization header as a Bearer token:
curl https://ai.pofano.com/v1/chat/completions \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"model": "gpt-4o", "messages": [{"role": "user", "content": "Hello!"}]}'Alternative Authentication Formats#
Pofano also supports these alternative authentication methods for compatibility with other providers:
| Format | Usage | Example |
|---|---|---|
x-api-key | Claude-compatible header | x-api-key: YOUR_API_KEY |
| Query parameter | Gemini-compatible URL param | ?key=YOUR_API_KEY |
x-goog-api-key | Google AI-compatible header | x-goog-api-key: YOUR_API_KEY |
Security Best Practices#
- Never expose API keys in client-side code such as browser JavaScript or mobile apps.
- Use environment variables to store keys (e.g.,
process.env.API_KEY). - Rotate keys regularly through the Pofano dashboard.
- Use separate keys for development and production environments.
- Set usage limits on your API keys to prevent unexpected charges.
Pofano