bing news search api 401 invalid subscription key error
This skill fixes Bing News Search API 401 invalid-subscription-key errors. Use it when news search calls fail auth or when setting up access. It is not for quota or permission errors; the fix is the exact header, a clean key value, region-matched endpoints, and rotation when exposed.
Bing News Search API 401 invalid subscription key
TL;DR
A 401 from the Bing News Search API means the subscription key is missing, wrong, or tied to a different Azure region than the endpoint you called. The fix is key hygiene: copy the key fresh from the Azure portal, send it in the Ocp-Apim-Subscription-Key header, and call the endpoint in the key's region. Rotate the key if it was ever committed to a repo or log.
The error
HTTP 401 Unauthorized
{"error": {"code": "401", "message": "Access denied due to invalid subscription key."}}When this helps
- Bing News Search calls return 401
- a news pipeline's key stops working
- setting up Bing Search API access for the first time
- rotating an exposed subscription key
When it doesn't
- the error is 403; that is quota or permissions, not the key
- the error is 429; that is rate limiting
- you need news from a region Bing does not cover well; re-source instead
Works with
Bing Search API v7 as of 2026; Azure portal for key management. Header and endpoint are version-specific.
Steps
1. Send the key in the correct header to the correct regional endpoint
curl -s "https://api.bing.microsoft.com/v7.0/news/search?q=[topic]" -H "Ocp-Apim-Subscription-Key: ${BING_KEY}" -o bing.json -w "HTTP %{http_code}\n"
head -c 200 bing.json; echoExpected: HTTP 200 with news JSON. The header name is exact and case-sensitive; the endpoint region must match the key's region.
2. Verify the key value has no whitespace or truncation
import os
k = os.environ.get("BING_KEY", "")
print("length:", len(k))
print("has whitespace:", k.strip() != k)Expected: A 32-character key with no surrounding whitespace. Copy-paste from the portal often adds a trailing space or newline.
3. Check the key's region matches the endpoint
printf 'Bing Search keys are provisioned in an Azure region. A key created in\nwestus called against api.bing.microsoft.com works, but keys bound to\nspecific regional endpoints must call that region. When in doubt, create\nthe key in the portal and use the endpoint shown next to it.\n' | tee region_check.txt
cat region_check.txtExpected: The region rule written down. Region mismatch is the most common 401 after a correct key.
4. Rotate the key if it was ever exposed
printf 'If the old key appeared in a repo, log, or chat, regenerate it in the\nAzure portal and update the secret store. Test the new key with the\nstep-1 call before deleting the old one.\n' | tee rotate_check.txt
cat rotate_check.txtExpected: A rotation checklist. Keys in git history stay valid until regenerated, so rotation is the only cleanup.
Other ways people phrase this
bing news api invalid subscription key
Key, header, or region. Check all three in order.
ocp-apim-subscription-key 401
The header name is the usual typo. Copy it exactly.
bing search api access denied key
Region mismatch after a correct key. Use the portal's shown endpoint.
Why it happens
Bing Search authenticates with a subscription key sent in a specific header to a region-matched endpoint. The 401 means one of the three is wrong: the key value, the header name, or the region. Azure does not distinguish these in the error, so check them in order.
Edge cases
- Keys have no expiry by default; a sudden 401 on a working key usually means it was regenerated or the resource was moved.
- The same key works across Bing Search APIs (web, news, images); quota is shared.
- Storing the key in environment config avoids the whitespace bugs of pasted values.
- Monitor quota in the Azure portal; 401s can mask an exhausted subscription.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstrMOS61DWfKBFskOcCyXbA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.