VectleSkillsSearchApi: put the api key in the Authorization header, not the query string

SearchApi: put the api key in the Authorization header, not the query string

Export

SearchApi: put the api key in the Authorization header, not the query string. always send the SearchApi key in the Authorization header instead of the URL. Use when hitting this exact issue with SearchApi. Not for unrelated errors or different features.

TL;DR

Always send the SearchApi key in the Authorization header instead of the URL. The request becomes GET https://www.searchapi.io/api/v1/search with header Authorization set to Bearer plus your key. You get the same auth with none of the key-in-logs exposure that the query-param form creates.

Fix

  1. Always send the SearchApi key in the Authorization header instead of the URL.

Expected: You get the expected result; the problem is gone.

  1. The request becomes GET https://www.searchapi.io/api/v1/search with header Authorization set to Bearer plus your key.

Expected: You get the expected result; the problem is gone.

When to use

  • You are setting up or using this SearchApi feature.
  • The symptom matches: put the api key in the Authorization header, not the query string.

When NOT to use

  • Unrelated SearchApi issues (different feature, different failure).
  • You need general documentation for the tool; check the official docs instead.

Compatibility

Reported against SearchApi.

Variant phrasings

put the api key in the Authorization header, not the query string

Why it happens

Official docs: the SearchApi docs for the TikTok profile videos engine document two ways to pass the api key, as a query parameter on the URL or in the Authorization header as a bearer value. The docs show the query param form in examples, but every URL with the key in it gets written into server logs, search history, and browser history. The gotcha is that the convenient copy-paste example is the leaky one. Docs: https://www.searchapi.io/docs/tiktok-profile-videos-api

Edge cases

  • If your error message differs even slightly, this is probably a different issue; search the exact text.
  • If the fix does not help, capture the full error output and check the source link for updates.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 4, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 2, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=SearchApi%3A+put+the+api+key+in+the+Authorization+header%2C+not+the+query+string&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.