X-TheRundown-Key
header. Keep the key in a private environment variable; never place it in a URL,
prompt, browser bundle, mobile app bundle, or public repository.
Header authentication
Pass your API key in theX-TheRundown-Key request header from a server-side
application.
Code Examples
Compatibility
Use header authentication for new and updated integrations. The OpenAPI contract retains query authentication for compatibility with existing clients, including the legacy V1 reference.WebSocket authentication
V2 WebSocket clients authenticate the upgrade request with the sameX-TheRundown-Key header from a server-side environment variable. Native
browser WebSocket clients cannot set custom headers; connect browsers to an
authenticated backend relay, which keeps the key on your server. WebSocket
access requires an Ultra plan or higher.
Public Endpoints
The following endpoints do not require authentication and can be called without an API key:
These endpoints are useful for bootstrapping your application with reference data before making authenticated requests.
Security Best Practices
Never expose keys in client-side code
Never expose keys in client-side code
API keys embedded in frontend JavaScript, mobile app bundles, or public repositories can be extracted by anyone. Always route API calls through your own backend server.
Use environment variables
Use environment variables
Store your API key in an environment variable rather than hardcoding it in source files. This prevents accidental commits to version control and makes key rotation straightforward.
Python
Node.js
Rotate keys if compromised
Rotate keys if compromised
If you suspect your API key has been exposed, contact TheRundown support immediately to rotate your key. Update all services that reference the old key as part of the rotation.
Use separate keys per environment
Use separate keys per environment
Maintain distinct API keys for development, staging, and production. This limits the blast radius if a non-production key is leaked and makes it easier to track usage per environment.