Skip to main content
Your API key works across all SportsAPI Pro endpoints — Football, Basketball, Tennis, Baseball, and every other sport. One key, all sports.

API Key Authentication

All API requests require the x-api-key header:
Never share your API key publicly or commit it to version control. Treat it like a password.

Getting Your API Key

  1. Sign up at sportsapipro.com/register
  2. Go to your Dashboard
  3. Copy your API key from the API Credentials section

Regenerating Your Key

If your API key is compromised:
  1. Go to your Dashboard
  2. Click Regenerate Token
  3. Update all applications with the new key
Regenerating immediately invalidates the old key. All applications using it will stop working.

Security Best Practices

Store your API key in environment variables:
Always make API requests from your backend. Never expose your API key in client-side JavaScript or mobile apps.
Check your usage regularly via the /status endpoint or your Dashboard. Unexpected spikes may indicate a compromised key.

Authentication Errors

Error Response

V1 vs V2 vs V3 Authentication

All three API versions use the same x-api-key header. The same API key works across all versions:

WebSocket Authentication

WebSocket connections authenticate via the x-api-key query parameter:
V2 WebSocket requires a JSON subscription message after connecting. V1 WebSocket streams updates automatically upon connection. See the WebSocket Guide for full details.
Last modified on June 29, 2026