What it is
YCloud uses API keys to identify your account and authorize API requests. Send the key only from trusted server-side code.Before you begin
Create or retrieve an API key in your YCloud account. Decide where each environment will store its secret before you add the key to application code.Request
Send the key in theX-API-Key header on every request.
Bearer prefix. The header value is the API key itself.
Response
Valid credentials allow the endpoint to return its normal success response. Invalid or unauthorized credentials return a4xx error response.
Store keys securely
- Keep API keys in a secret manager or an encrypted environment variable.
- Use API keys only in trusted server-side code.
- Never place a key in a URL, browser bundle, mobile application, log, or screenshot.
- Use separate keys for separate environments when your account setup allows it.
- Rotate a key immediately if you believe it has been exposed.
Rotate a key
Create or select the replacement key, deploy it to every service that calls YCloud, verify traffic with the new key, and then revoke the old key. If you suspect exposure, rotate first and investigate afterward.Troubleshoot authentication
An authentication failure returns a4xx response. Check that:
- The request uses
https://api.ycloud.com/v2. - The header name is exactly
X-API-Key. - The key does not contain extra spaces or quotation marks.
- The key is active and belongs to the intended YCloud account.
- The account can access the product used by the endpoint.
requestId for troubleshooting, but never log the API key. See Errors for the response format.
Test authentication
Verify a key with a read-only Balance API request.

