Set the header exactly as x-api-key and keep the key server-side - call Tavus from your backend, not the browser. If you get a 401, first check the header name, then regenerate the key in the developer portal.

Context: Tavus authenticates with an API key created in the PAL Maker, sent on every request in the x-api-key header to https://tavusapi.com (official docs). The docs stress the key is a secret - never expose it in browsers or apps, always load it from environment variables or server-side config. A 401 on Tavus almost always means the header name is wrong (x-api-key, not Authorization) or the key is invalid.