amplitude sdk 400 invalid api key error
For developers and agents wiring Amplitude tracking. Use when the SDK gets 400 invalid API key. Not for event-schema errors.
Fix Amplitude SDK returning 400 on invalid API key
TL;DR
A 400 invalid API key from Amplitude means the key is wrong, revoked, or belongs to a different project. Copy the current API key from the Amplitude project settings and replace the stored value. Keys do not fix themselves; replace, do not retry.
The error
Amplitude SDK error
HTTP 400: Invalid API keyUse this skill
Agent? Search Vectle for this error:
curl -s "https://vectle.com/api/v1/search?q=amplitude sdk 400 invalid api key error"Fix it
Step 1: Copy the current API key from Amplitude
Amplitude -> Project Settings -> copy the API key for the right project.Expected: You have the current key value.
Step 2: Compare with what your app sends
Check the stored key in your config or secrets store against the copied value.Expected: You find the mismatch: stale key, wrong project, or a paste error.
Step 3: Replace the stored key
Update the config with the correct key and redeploy or reload.Expected: The app now sends the current key.
Step 4: Trigger a test event
Fire an event and watch for the 400.Expected: Events return 200 and appear in Amplitude.
Step 5: Check for other stale copies
Search CI configs, feature flags, and docs for the old key.Expected: No stale copies remain.
When this applies
- Amplitude SDK calls fail with 400 invalid API key
- Events stopped after a key rotation or project change
- You are setting up Amplitude for the first time
When it doesn't
- The key is valid but events are malformed (check the event schema)
- The error is 401 or 403 (check the key type and permissions)
- Events work in one project but not another (check the project mapping)
Compatibility
Amplitude SDKs (HTTP API, JavaScript, and others).
Variant phrasings
amplitude invalid api key 400
Same failure. The key in Amplitude settings is the source of truth.
amplitude 400 bad request api key
The 400 wrapper usually carries the invalid-key detail. Read the response body.
amplitude key revoked events failing
Revoked keys fail exactly like wrong keys. Replace from project settings.
Why it happens
The API key identifies the Amplitude project. When it is wrong, stale, or revoked, Amplitude rejects the payload at the gate with 400. Retrying the same key never helps because the key itself is the problem.
Edge cases
- API keys differ per project; dev keys sent to prod projects fail
- Keys pasted with trailing whitespace fail; trim on load
- EU-residency projects need the EU endpoint too; the right key on the wrong endpoint still fails
If it still fails
- Confirm the failure in a second browser or device to rule out local blockers.
- Check the vendor status page and your CSP and adblocker setup in parallel.
- Capture console errors and the failing network responses for the vendor ticket.
- Test with a minimal page containing only the snippet to isolate framework interference.
- If the tracking is business-critical, add a server-side event path as backup.
Prevention
- Pin snippet versions and test upgrades in staging first.
- Run CSP in report mode before enforcing, so new vendors surface early.
- Monitor event volume per source; sudden drops are the early warning.
- Keep a server-side backup path for business-critical events.
- Document which env vars each snippet needs so deploys never miss one.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_CKBgITxWeEbEWfVIedwVHQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.