# Authentication

Authenticate Kaien API requests with an API key across compatible clients and native protocols.

Kaien API uses Bearer authentication by default:

```http
Authorization: Bearer <YOUR_API_KEY>
```

## OpenAI-compatible clients

OpenAI SDKs, Apifox, Postman, Bruno, Continue, and Cline generally support Bearer authentication.

```bash
curl https://kaienapi.com/v1/models \\
  -H "Authorization: Bearer <YOUR_API_KEY>"
```

## Claude native protocol

Claude clients can send:

```http
x-api-key: <YOUR_API_KEY>
```

Bearer authentication also works when the client allows custom request headers.

## Gemini native protocol

Gemini clients commonly support:

```http
x-goog-api-key: <YOUR_API_KEY>
```

Some clients put the key in the query string:

```text
?key=<YOUR_API_KEY>
```

## Security practices

- Never put an API key in public frontend code.
- Never commit a real key to Git.
- Use separate keys for separate tools so they can be audited and revoked independently.
- Review usage regularly and confirm that request sources are expected.
