Kaien API uses Bearer authentication by default:

OpenAI-compatible clients

OpenAI SDKs, Apifox, Postman, Bruno, Continue, and Cline generally support Bearer authentication.

Claude native protocol

Claude clients can send:
Bearer authentication also works when the client allows custom request headers.

Gemini native protocol

Gemini clients commonly support:
Some clients put the key in the query string:

Security practices

  • Never put an API key in public frontend code.
  • Never commit a real key to Git.
  • Use separate keys for separate tools so they can be audited and revoked independently.
  • Review usage regularly and confirm that request sources are expected.