Getting Started / Authentication

Authentication

Every request is authenticated with your API key, sent in a request header. There are no tokens to refresh and no sessions to manage.

Overview

GoSportsAPI uses API keys. Send your key in the x-api-key header on every request to https://api.gosportsapi.com/v1. The base URL uses HTTPS, so your key is encrypted in transit.

Don’t have a key yet? API Keys explains how to create one and keep it safe.

Sending your key

Add this header to every request.

x-api-key: YOUR_API_KEY

For example, to list football fixtures:

curl -X GET \
"https://api.gosportsapi.com/v1/football/fixtures" \
-H "x-api-key: YOUR_API_KEY"

Keep keys out of URLs

Always send the key as a header, never as a query parameter. URLs end up in server logs, browser history and analytics tools.

Call the API from a server

Anyone who has your key can spend your plan’s requests. Keep it on infrastructure you control:

  • Store it in an environment variable or a secret manager — never in source control.
  • Don’t ship it in browser JavaScript, mobile apps or desktop apps. Anything you distribute can be unpacked.
  • Put a small backend route between your front end and the API. It adds the header and returns only the data your UI needs — and it is the natural place to cache.
// GET /api/live — your endpoint, called by your front end
export async function GET() {
const res = await fetch("https://api.gosportsapi.com/v1/football/fixtures/live", {
headers: { "x-api-key": process.env.GOSPORTS_API_KEY },
});
const { data } = await res.json();
return Response.json(data);
}

Authentication errors

If the header is missing, or the key is mistyped or has been revoked, the API responds with 401 Unauthorized:

401 Unauthorized · application/json
{
"error": {
"status": 401,
"message": "Missing or invalid API key"
}
}

If you get a 401, check that:

  • The header is named x-api-key (header names are case-insensitive, so X-API-Key works too).
  • The value is the key alone, with no quotes, spaces or “Bearer” prefix.
  • The key hasn’t been rotated or revoked.
  • You are calling https://api.gosportsapi.com/v1.

A valid key that has used up its limits gets 429, not 401 — see Rate Limits.