# API: Can I authenticate without putting the key in the URL?

**URL:** https://meta.discourse.org/t/api-can-i-authenticate-without-putting-the-key-in-the-url/29425
**Category:** Development
**Tags:** rest-api
**Created:** [2015年五月29日 18:17 UTC](https://meta.discourse.org/t/api-can-i-authenticate-without-putting-the-key-in-the-url/29425 "2015-05-29T18:17:35Z")
**Posts on this page:** 1
**Showing post:** 14

<div class="post-metadata">

### Author: ![simon](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/simon/32/339122_2.png) [@simon](https://meta.discourse.org/u/simon)
#### Post date: [2019年五月10日 23:18 UTC](https://meta.discourse.org/t/api-can-i-authenticate-without-putting-the-key-in-the-url/29425/14 "2019-05-10T23:18:51Z")

</div>

The Discourse API now supports, and recommends passing the authentication details in the request’s HTTP headers. See the updated [Discourse REST API Documentation](https://meta.discourse.org/t/discourse-api-documentation/22706) topic and the Authentication section of [https://docs.discourse.org/](https://docs.discourse.org/) for details.

---

_[View the full topic](https://meta.discourse.org/t/api-can-i-authenticate-without-putting-the-key-in-the-url/29425)._
