API Error: Invalid API Key / Incorrect API key provided
The API didn’t recognise the key sent with the request — it’s wrong, revoked, from another environment, or sent in the wrong place.
Meaning
API keys must be sent exactly as the provider expects (header name and scheme vary). A key that worked yesterday may have been rotated, revoked, restricted to certain IPs/referrers, or belong to a test/sandbox environment while you call production.
Common causes
- Typo, truncation or extra whitespace/newline in the key (common with env files and copy-paste)
- Wrong header:
Authorization: BearervsX-API-Keyvs query parameter - Test key used against live API (or vice versa)
- Key revoked, rotated or expired
- Key restricted by IP, HTTP referrer or app package
- Environment variable not loaded in this process (empty key)
⚡ Quick fix
- Print the key length and first/last 4 characters (never the whole key) to confirm it’s loaded
- Check the provider docs for the exact header
- Confirm environment (test vs live) and regenerate the key if unsure
- Review key restrictions in the provider console
Detailed fix by platform
Node.js
- Fail fast when the key is missing:javascript
const key = process.env.PAYMENTS_API_KEY?.trim(); if (!key) throw new Error('PAYMENTS_API_KEY is not set'); console.log(`Using key ${key.slice(0, 4)}…${key.slice(-4)} (${key.length} chars)`);
PHP
- Trim values read from .env / config:
trim(getenv('API_KEY'))— a trailing newline makes the key invalid.
How to diagnose
- Loaded — Is the key present in this process (length > 0)?
- Format — Right header/scheme and no stray whitespace?
- Environment — Test vs live, right project/account?
- Restrictions — IP/referrer/app restrictions on the key?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026