# GenderAPI authentication

> Authenticate server-side GenderAPI calls without exposing the API key.

Canonical HTML: https://www.genderapi.io/docs-authentication

Last reviewed: 2026-09-14

## Bearer authentication

Bearer authentication is the recommended transport for POST requests.

```http
Authorization: Bearer YOUR_API_KEY
Content-Type: application/json
```

## Credential safety

- Store the key in a server-side secret manager or environment variable.
- Never expose it in browser code, repositories, logs, screenshots, or prompts.
- Keep documented query-key requests server-side and redact query strings.
- Rotate a key that may have leaked.

- [OpenAPI security schemes](https://www.genderapi.io/openapi/openapi.json)
