# Fix Amplitude SDK returning 400 on invalid API key

## TL;DR
A 400 invalid API key from Amplitude means the key is wrong, revoked, or belongs to a different project. Copy the current API key from the Amplitude project settings and replace the stored value. Keys do not fix themselves; replace, do not retry.

## The error
```text
Amplitude SDK error
HTTP 400: Invalid API key
```

## Use this skill
Agent? Search Vectle for this error:
```bash
curl -s "https://vectle.com/api/v1/search?q=amplitude sdk 400 invalid api key error"
```

## Fix it

### Step 1: Copy the current API key from Amplitude

```bash
Amplitude -> Project Settings -> copy the API key for the right project.
```

Expected: You have the current key value.

### Step 2: Compare with what your app sends

```bash
Check the stored key in your config or secrets store against the copied value.
```

Expected: You find the mismatch: stale key, wrong project, or a paste error.

### Step 3: Replace the stored key

```bash
Update the config with the correct key and redeploy or reload.
```

Expected: The app now sends the current key.

### Step 4: Trigger a test event

```bash
Fire an event and watch for the 400.
```

Expected: Events return 200 and appear in Amplitude.

### Step 5: Check for other stale copies

```bash
Search CI configs, feature flags, and docs for the old key.
```

Expected: No stale copies remain.

## When this applies

- Amplitude SDK calls fail with 400 invalid API key
- Events stopped after a key rotation or project change
- You are setting up Amplitude for the first time

## When it doesn't

- The key is valid but events are malformed (check the event schema)
- The error is 401 or 403 (check the key type and permissions)
- Events work in one project but not another (check the project mapping)

## Compatibility

Amplitude SDKs (HTTP API, JavaScript, and others).

## Variant phrasings

### amplitude invalid api key 400

Same failure. The key in Amplitude settings is the source of truth.

### amplitude 400 bad request api key

The 400 wrapper usually carries the invalid-key detail. Read the response body.

### amplitude key revoked events failing

Revoked keys fail exactly like wrong keys. Replace from project settings.

## Why it happens

The API key identifies the Amplitude project. When it is wrong, stale, or revoked, Amplitude rejects the payload at the gate with 400. Retrying the same key never helps because the key itself is the problem.

## Edge cases

- API keys differ per project; dev keys sent to prod projects fail
- Keys pasted with trailing whitespace fail; trim on load
- EU-residency projects need the EU endpoint too; the right key on the wrong endpoint still fails

## If it still fails

- Confirm the failure in a second browser or device to rule out local blockers.
- Check the vendor status page and your CSP and adblocker setup in parallel.
- Capture console errors and the failing network responses for the vendor ticket.
- Test with a minimal page containing only the snippet to isolate framework interference.
- If the tracking is business-critical, add a server-side event path as backup.

## Prevention

- Pin snippet versions and test upgrades in staging first.
- Run CSP in report mode before enforcing, so new vendors surface early.
- Monitor event volume per source; sudden drops are the early warning.
- Keep a server-side backup path for business-critical events.
- Document which env vars each snippet needs so deploys never miss one.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_CKBgITxWeEbEWfVIedwVHQ
