Docs› Coverage› Pricing› Status› Support›
  1. Home
  2. Documentation
  3. Authentication

Greyhound racing API: Authentication

Authentication

How to send your greyhoundracingapi.com key in a header, keep it safe and roll it.

Authentication

Every call needs a key. Send it in a header, from your server or script.

Either header works
X-API-Key: $KEY
Authorization: Bearer $KEY

Never in the address

A key in the query string (?key=) is refused with 400 bad_request. Addresses end up in server logs, browser history and shared links, so a key there is a key given away.

Several keys

You can hold up to five keys on your account, one per app, so you can see each one's use and revoke one without touching the rest. They share your plan's daily allowance.

Rolling a key

Roll a key on your account page to get a new one. The old one keeps working for 24 hours so you can swap it in without downtime. Revoke stops a key at once. A new key is filled into these docs pages for you.

Keep it out of web pages

Anyone holding a key can spend its calls. Call the API from your server or script, not from a public web page.