# Bing News Search API 401 invalid subscription key

## TL;DR
A 401 from the Bing News Search API means the subscription key is missing, wrong, or tied to a different Azure region than the endpoint you called. The fix is key hygiene: copy the key fresh from the Azure portal, send it in the Ocp-Apim-Subscription-Key header, and call the endpoint in the key's region. Rotate the key if it was ever committed to a repo or log.

## The error
```text
HTTP 401 Unauthorized
{"error": {"code": "401", "message": "Access denied due to invalid subscription key."}}
```

## When this helps
- Bing News Search calls return 401
- a news pipeline's key stops working
- setting up Bing Search API access for the first time
- rotating an exposed subscription key

## When it doesn't
- the error is 403; that is quota or permissions, not the key
- the error is 429; that is rate limiting
- you need news from a region Bing does not cover well; re-source instead

## Works with
Bing Search API v7 as of 2026; Azure portal for key management. Header and endpoint are version-specific.

## Steps
### 1. Send the key in the correct header to the correct regional endpoint
```bash
curl -s "https://api.bing.microsoft.com/v7.0/news/search?q=[topic]" -H "Ocp-Apim-Subscription-Key: ${BING_KEY}" -o bing.json -w "HTTP %{http_code}\n"
head -c 200 bing.json; echo
```
Expected: HTTP 200 with news JSON. The header name is exact and case-sensitive; the endpoint region must match the key's region.

### 2. Verify the key value has no whitespace or truncation
```python
import os
k = os.environ.get("BING_KEY", "")
print("length:", len(k))
print("has whitespace:", k.strip() != k)
```
Expected: A 32-character key with no surrounding whitespace. Copy-paste from the portal often adds a trailing space or newline.

### 3. Check the key's region matches the endpoint
```bash
printf 'Bing Search keys are provisioned in an Azure region. A key created in\nwestus called against api.bing.microsoft.com works, but keys bound to\nspecific regional endpoints must call that region. When in doubt, create\nthe key in the portal and use the endpoint shown next to it.\n' | tee region_check.txt
cat region_check.txt
```
Expected: The region rule written down. Region mismatch is the most common 401 after a correct key.

### 4. Rotate the key if it was ever exposed
```bash
printf 'If the old key appeared in a repo, log, or chat, regenerate it in the\nAzure portal and update the secret store. Test the new key with the\nstep-1 call before deleting the old one.\n' | tee rotate_check.txt
cat rotate_check.txt
```
Expected: A rotation checklist. Keys in git history stay valid until regenerated, so rotation is the only cleanup.

## Other ways people phrase this
### bing news api invalid subscription key
Key, header, or region. Check all three in order.

### ocp-apim-subscription-key 401
The header name is the usual typo. Copy it exactly.

### bing search api access denied key
Region mismatch after a correct key. Use the portal's shown endpoint.

## Why it happens
Bing Search authenticates with a subscription key sent in a specific header to a region-matched endpoint. The 401 means one of the three is wrong: the key value, the header name, or the region. Azure does not distinguish these in the error, so check them in order.

## Edge cases
- Keys have no expiry by default; a sudden 401 on a working key usually means it was regenerated or the resource was moved.
- The same key works across Bing Search APIs (web, news, images); quota is shared.
- Storing the key in environment config avoids the whitespace bugs of pasted values.
- Monitor quota in the Azure portal; 401s can mask an exhausted subscription.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_rMOS61DWfKBF_skOcCyXbA
