# Authentication

Every request needs an API key. Keys are 32-character strings issued on the [API dashboard](https://twitterscore.io/api-dashboard/); an account can have several named keys that share one plan quota.

## Preferred: `X-API-Key` header

```bash
curl -s "https://twitterscore.io/api/v1/get_twitter_score?username=VitalikButerin" -H "X-API-Key: $TWITTERSCORE_API_KEY"
```

## Also accepted: Bearer token

The same key as `Authorization: Bearer <key>`. Useful for tool runners and MCP clients that only know how to send a Bearer header.

## Compatibility: `api_key` query parameter

The original form, `?api_key=<key>`, keeps working. Avoid it in new code: keys in URLs end up in proxy logs, browser history and referer headers. If both a query key and a header are present, the query key is used.

## Key lifecycle

- Revoke and re-create keys on the dashboard at any time; a revoked key returns `api_key_revoked`.
- When the plan expires or is cancelled, all keys stop working with `api_access_deactivated` until renewal.
- `GET https://twitterscore.io/api/v1/limits` returns the plan limits and remaining quota for the calling key.

## Keep keys secret

Call the API from your backend, not from browser JavaScript. Store keys in environment variables (`TWITTERSCORE_API_KEY` in our examples).