Authentication and URLs
Send API keys in request headers. Never place them in URLs, frontend JavaScript, public configuration, or ordinary application logs.
OpenAI compatible and Responses
http
Authorization: Bearer sk-your-key
Content-Type: application/jsonBearer must be followed by one space. Replace only sk-your-key. The base URL is:
text
https://sprelaytoken.com/v1Claude Messages
http
x-api-key: sk-your-key
anthropic-version: 2023-06-01
content-type: application/jsonx-api-key contains the key without a Bearer prefix. anthropic-version selects the protocol version. Claude SDKs use this root base URL and append /v1/messages:
text
https://sprelaytoken.comGemini Native
http
x-goog-api-key: sk-your-key
Content-Type: application/jsonThe model is part of the native request path:
text
https://sprelaytoken.com/v1beta/models/{model}:generateContentEnvironment variables
bash
# Replace only the placeholder; later commands read this variable.
export SPRELAY_API_KEY="sk-your-key"powershell
# This value is temporary and applies to the current PowerShell session.
$env:SPRELAY_API_KEY = "sk-your-key"dotenv
# .env uses KEY=VALUE without export or spaces around the equals sign.
SPRELAY_API_KEY=sk-your-keyAdd .env to .gitignore. Commit only an empty .env.example.
Common URL mistakes
| Resulting URL | Cause |
|---|---|
.../v1/v1/chat/completions | Both the client and configuration appended /v1 |
.../chat/completions/chat/completions | A complete endpoint was entered in a Base URL field |
| Claude path with OpenAI JSON | The endpoint and request body use different protocols |
| Gemini SDK with an unexpected Bearer header | The SDK expects its API-key option or x-goog-api-key |
