logoPofano

Authentication

How to authenticate requests to the Pofano API.

Overview#

Pofano supports multiple authentication methods to accommodate different API conventions. The standard method is Bearer token authentication via the Authorization header.

Bearer Token (Standard)#

For OpenAI-compatible endpoints, use the Authorization header with your API key:

Authorization: Bearer YOUR_API_KEY

This is the recommended and most widely supported method. It works across the OpenAI-compatible text endpoints documented on this site, including chat completions, responses, completions, model lookup, and most provider-compatible relay routes.

Alternative Formats#

Claude / Anthropic Format#

For endpoints that follow Anthropic's API convention, you can use the x-api-key header:

x-api-key: YOUR_API_KEY

Gemini / Google Format#

For Google-compatible Gemini endpoints, you can pass your API key as a query parameter. Use the Gemini-native v1beta routes for model listing and generation:

https://ai.pofano.com/v1beta/models?key=YOUR_API_KEY

You can also use the same key with Gemini generation routes such as:

https://ai.pofano.com/v1beta/models/gemini-2.0-flash:generateContent?key=YOUR_API_KEY

Security Best Practices#

  • Never expose your API key in client-side code or public repositories.
  • Use environment variables to store your key in production applications.
  • Rotate keys regularly and revoke keys that are no longer in use.
  • Set per-key quotas to limit potential damage from a compromised key.
  • Use HTTPS for all API requests — plain HTTP connections will be rejected.

On this page