Authentication
Every /v1/* request needs your gateway API key. The gateway accepts two header styles.
The two header styles
http
Authorization: Bearer sk-xxxxxxxxxxxx
# or
x-api-key: sk-xxxxxxxxxxxxPrecedence
If both headers are present, Authorization: Bearer takes precedence.
Authorization: Bearer …x-api-key: …?key=…(query param — for quick browser tests only)
Security
Avoid the query param in production — URLs end up in proxy and browser logs.
Per-tool notes
Anthropic SDK / Claude Code — uses x-api-key internally. Claude Code sends ANTHROPIC_AUTH_TOKEN as Bearer.
OpenAI SDK — uses Authorization: Bearer automatically from the api_key option.
Try it
bash
curl https://api.laalaa.me/v1/models \ -H "Authorization: Bearer sk-xxxxxxxxxxxx"200— key works401 missing_api_key— no header sent401 invalid_api_key— key unknown, expired, revoked, or exhausted
ទំព័រនេះមានប្រយោជន៍?