Authentication overview
Choose how to send your API key
All authenticated requests require a valid GenderAPI key. The Authorization header is the recommended default because it separates credentials from your request data.
Recommended
Authorization header
Set Authorization: Bearer YOUR_API_KEY and send only the input parameters in the JSON body.
Authorization
Bearer YOUR_API_KEYcURL
curl -X POST "https://api.genderapi.io/api" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_KEY" \
-d '{"name":"Alice"}'JavaScript
fetch("https://api.genderapi.io/api", {
method: "POST",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_KEY"
},
body: JSON.stringify({ name: "Alice" })
});Alternative
API key in the JSON body
Include the key as the key property alongside your request data. Use this method only from trusted server-side code.
cURL
curl -X POST "https://api.genderapi.io/api" \
-H "Content-Type: application/json" \
-d '{"name":"Alice","key":"YOUR_API_KEY"}'Python
import requests
response = requests.post(
"https://api.genderapi.io/api",
json={
"name": "Alice",
"key": "YOUR_API_KEY"
}
)
print(response.json())Credential safety
Protect your API key
- Store keys in server-side environment variables or a secrets manager.
- Never commit a key to source control or expose it in browser JavaScript.
- Remove credentials from application, proxy and analytics logs.
- Use HTTPS for every request and replace a key if it may have leaked.
Quick comparison
Which method should you use?
| Method | Best for | Credential location |
|---|---|---|
| Bearer tokenRecommended | Most server integrations | Authorization header |
| JSON body | Existing POST integrations | key property |
POST content type: Set
Content-Type: application/json when sending a JSON request body.Next guide