API keys in headers or query parameters
Some providers expect a custom header such as X-API-Key; others require a named query parameter. Match both the parameter name and location. Query credentials can appear in the provider’s access logs. In our playground, request URLs stay out of the address bar and are not saved to browser storage.
Bearer tokens and OAuth
A bearer token is sent using the Authorization: Bearer header. Anyone who possesses it may be able to use its permissions. The playground accepts an existing access token; it does not run an OAuth login or refresh-token flow. Obtain an appropriately scoped test token using the provider’s own process.
Basic authentication
Basic authentication encodes a username and password into an Authorization header; Base64 is not encryption. Use HTTPS and follow the provider’s credential rules. Browser access still depends on the provider permitting the Authorization header through CORS.
How credentials are handled here
The request editor keeps values in the current page’s memory and sends them directly to your chosen HTTPS API endpoint only when you press Send request. It does not use a Find Public APIs backend, cookies, local storage, or session storage for credentials. Leaving or reloading the page clears the editor; browser extensions and the receiving provider are outside our control.
Copy examples without accidentally sharing secrets
Code previews replace authentication values with placeholders by default. Custom headers and query values are also hidden in the default preview. Reveal values only when needed, and check copied snippets before sharing them. Response data can itself be sensitive and is shown as returned.
Further reading
Put it into practice.
Start with a reviewed guide or test a request in the playground.
Open the playground ↗Explore reviewed APIs →