Authentication
Every request is authenticated with your API key, sent in a request header. There are no tokens to refresh and no sessions to manage.
Overview
GoSportsAPI uses API keys. Send your key in the x-api-key header on every request to https://api.gosportsapi.com/v1. The base URL uses HTTPS, so your key is encrypted in transit.
Don’t have a key yet? API Keys explains how to create one and keep it safe.
Sending your key
Add this header to every request.
For example, to list football fixtures:
curl -X GET \ "https://api.gosportsapi.com/v1/football/fixtures" \ -H "x-api-key: YOUR_API_KEY"Keep keys out of URLs
Always send the key as a header, never as a query parameter. URLs end up in server logs, browser history and analytics tools.
Call the API from a server
Anyone who has your key can spend your plan’s requests. Keep it on infrastructure you control:
- Store it in an environment variable or a secret manager — never in source control.
- Don’t ship it in browser JavaScript, mobile apps or desktop apps. Anything you distribute can be unpacked.
- Put a small backend route between your front end and the API. It adds the header and returns only the data your UI needs — and it is the natural place to cache.
// GET /api/live — your endpoint, called by your front endexport async function GET() { const res = await fetch("https://api.gosportsapi.com/v1/football/fixtures/live", { headers: { "x-api-key": process.env.GOSPORTS_API_KEY }, }); const { data } = await res.json(); return Response.json(data);}Authentication errors
If the header is missing, or the key is mistyped or has been revoked, the API responds with 401 Unauthorized:
{ "error": { "status": 401, "message": "Missing or invalid API key" }}If you get a 401, check that:
- The header is named
x-api-key(header names are case-insensitive, soX-API-Keyworks too). - The value is the key alone, with no quotes, spaces or “Bearer” prefix.
- The key hasn’t been rotated or revoked.
- You are calling
https://api.gosportsapi.com/v1.
A valid key that has used up its limits gets 429, not 401 — see Rate Limits.