Skip to main content
Authenticate server-side requests with your API key in the X-TheRundown-Key header. Keep the key in a private environment variable; never place it in a URL, prompt, browser bundle, mobile app bundle, or public repository.

Header authentication

Pass your API key in the X-TheRundown-Key request header from a server-side application.

Code Examples

Compatibility

Use header authentication for new and updated integrations. The OpenAPI contract retains query authentication for compatibility with existing clients, including the legacy V1 reference.

WebSocket authentication

V2 WebSocket clients authenticate the upgrade request with the same X-TheRundown-Key header from a server-side environment variable. Native browser WebSocket clients cannot set custom headers; connect browsers to an authenticated backend relay, which keeps the key on your server. WebSocket access requires an Ultra plan or higher.

Public Endpoints

The following endpoints do not require authentication and can be called without an API key: These endpoints are useful for bootstrapping your application with reference data before making authenticated requests.

Security Best Practices

API keys embedded in frontend JavaScript, mobile app bundles, or public repositories can be extracted by anyone. Always route API calls through your own backend server.
Store your API key in an environment variable rather than hardcoding it in source files. This prevents accidental commits to version control and makes key rotation straightforward.
Python
Node.js
If you suspect your API key has been exposed, contact TheRundown support immediately to rotate your key. Update all services that reference the old key as part of the rotation.
Maintain distinct API keys for development, staging, and production. This limits the blast radius if a non-production key is leaked and makes it easier to track usage per environment.