API Keys
Your API key identifies your account on every request and counts usage against your plan. Treat it like a password.
Get a key
- Create a free account, or sign in.
- Open API keys in your dashboard and create a key.
- Give it a name you will recognise later, such as
production-serverorlocal-dev. - Copy the key into your secret manager or environment.
Or go straight to Get an API key.
Store your key
Keep keys out of your source code. Load them from the environment at runtime, so the same code runs with a different key in each environment:
# .env — keep this file out of version controlGOSPORTS_API_KEY=your_api_key_hereconst API_KEY = process.env.GOSPORTS_API_KEY;if (!API_KEY) throw new Error("GOSPORTS_API_KEY is not set");const res = await fetch("https://api.gosportsapi.com/v1/football/leagues", { headers: { "x-api-key": API_KEY },});const { data } = await res.json();Committed a key by accident?
Add .env to .gitignore. If a key ever reaches a repository — even a private one — treat it as compromised and rotate it.
Multiple keys
Each account can hold up to [X] keys. Use a separate key for each environment and service — for example production, staging and local development — so you can rotate or revoke one without touching the others.
Requests made with any of your keys count towards your plan’s limits. See Rate Limits.
Rotate a key
Rotating replaces a key without downtime:
- Create a new key.
- Deploy it to every service that uses the old key.
- Check that traffic on the old key has stopped.
- Revoke the old key.
Rotate on a regular schedule, and whenever someone with access to your keys leaves the team.
Revoke a compromised key
If a key leaks — committed to a repository, pasted into a ticket, shipped inside an app — revoke it from your dashboard straight away, then create a replacement. Requests made with a revoked key get 401.
If you see usage you don’t recognise, contact us.