Authentication
How to authenticate requests to the Pofano API.
Overview#
Pofano supports multiple authentication methods to accommodate different API conventions. The standard method is Bearer token authentication via the Authorization header.
Bearer Token (Standard)#
For OpenAI-compatible endpoints, use the Authorization header with your API key:
Authorization: Bearer YOUR_API_KEYThis is the recommended and most widely supported method. It works across the OpenAI-compatible text endpoints documented on this site, including chat completions, responses, completions, model lookup, and most provider-compatible relay routes.
Alternative Formats#
Claude / Anthropic Format#
For endpoints that follow Anthropic's API convention, you can use the x-api-key header:
x-api-key: YOUR_API_KEYGemini / Google Format#
For Google-compatible Gemini endpoints, you can pass your API key as a query parameter. Use the Gemini-native v1beta routes for model listing and generation:
https://ai.pofano.com/v1beta/models?key=YOUR_API_KEYYou can also use the same key with Gemini generation routes such as:
https://ai.pofano.com/v1beta/models/gemini-2.0-flash:generateContent?key=YOUR_API_KEYSecurity Best Practices#
- Never expose your API key in client-side code or public repositories.
- Use environment variables to store your key in production applications.
- Rotate keys regularly and revoke keys that are no longer in use.
- Set per-key quotas to limit potential damage from a compromised key.
- Use HTTPS for all API requests — plain HTTP connections will be rejected.
Pofano