invalid_api_key 🔌 API

API Error: Invalid API Key / Incorrect API key provided

The API didn’t recognise the key sent with the request — it’s wrong, revoked, from another environment, or sent in the wrong place.

Seen on: Node.js PHP REST API

Meaning

API keys must be sent exactly as the provider expects (header name and scheme vary). A key that worked yesterday may have been rotated, revoked, restricted to certain IPs/referrers, or belong to a test/sandbox environment while you call production.

Common causes

  • Typo, truncation or extra whitespace/newline in the key (common with env files and copy-paste)
  • Wrong header: Authorization: Bearer vs X-API-Key vs query parameter
  • Test key used against live API (or vice versa)
  • Key revoked, rotated or expired
  • Key restricted by IP, HTTP referrer or app package
  • Environment variable not loaded in this process (empty key)

⚡ Quick fix

  1. Print the key length and first/last 4 characters (never the whole key) to confirm it’s loaded
  2. Check the provider docs for the exact header
  3. Confirm environment (test vs live) and regenerate the key if unsure
  4. Review key restrictions in the provider console

Detailed fix by platform

Node.js

  1. Fail fast when the key is missing:
    javascript
    const key = process.env.PAYMENTS_API_KEY?.trim();
    if (!key) throw new Error('PAYMENTS_API_KEY is not set');
    console.log(`Using key ${key.slice(0, 4)}…${key.slice(-4)} (${key.length} chars)`);

PHP

  1. Trim values read from .env / config: trim(getenv('API_KEY')) — a trailing newline makes the key invalid.

How to diagnose

  1. Loaded — Is the key present in this process (length > 0)?
  2. Format — Right header/scheme and no stray whitespace?
  3. Environment — Test vs live, right project/account?
  4. Restrictions — IP/referrer/app restrictions on the key?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.