Getting started
API authentication and security boundaries
Model requests authenticate directly at https://api.51cowork.com; account and Key lifecycle actions stay in Dashboard.
Use Authorization: Bearer <key>; Anthropic-compatible clients may use x-api-key. Keep the Key in a server Secret or local development environment.
- Bearer
- Recommended
- Anthropic
- x-api-key
- Invalid auth
- 401
- Browser
- Never direct
Authentication headers
| Use case | Header |
|---|---|
| General / OpenAI | Authorization: Bearer <API_KEY> |
| Anthropic compatible | x-api-key: <API_KEY> |
| Unsupported | URL query, Cookie, public browser variable |
Where the Key comes from
- 1Register or sign in to Dashboard.
- 2Open the API Keys page.
- 3Create and immediately store the complete Key safely.
- 4Configure it in a controlled Secret or user-level file.
Protect the Key
- Never put it in localStorage, URLs, analytics, public bundles, or logs.
- Never commit it to Git or paste it into issues, chats, or support tickets.
- After exposure, create a replacement, update clients, and delete the old Key.
