51cowork APIDocs
Open docs navigation

Getting started

API authentication and security boundaries

Model requests authenticate directly at https://api.51cowork.com; account and Key lifecycle actions stay in Dashboard.

Quick answer

Use Authorization: Bearer <key>; Anthropic-compatible clients may use x-api-key. Keep the Key in a server Secret or local development environment.

Bearer
Recommended
Anthropic
x-api-key
Invalid auth
401
Browser
Never direct
01

Authentication headers

Use caseHeader
General / OpenAIAuthorization: Bearer <API_KEY>
Anthropic compatiblex-api-key: <API_KEY>
UnsupportedURL query, Cookie, public browser variable
02

Where the Key comes from

  1. 1Register or sign in to Dashboard.
  2. 2Open the API Keys page.
  3. 3Create and immediately store the complete Key safely.
  4. 4Configure it in a controlled Secret or user-level file.
03

Protect the Key

  • Never put it in localStorage, URLs, analytics, public bundles, or logs.
  • Never commit it to Git or paste it into issues, chats, or support tickets.
  • After exposure, create a replacement, update clients, and delete the old Key.