Fixing "Missing Authorization header" on API calls
This 401 means the request arrived with no credential at all. It is different from a wrong key: the API never had anything to check.
What the error says
On /v1/chat/completions the response is HTTP 401:
{
"error": {
"message": "Missing Authorization header. Send: Authorization: Bearer sk-ww-...",
"type": "invalid_request_error",
"code": null,
"param": null
}
}On the Anthropic-style /v1/messages route the same condition returns 401 with type authentication_error.
Which headers count
The API reads the key from Authorization: Bearer <key> first, and falls back to x-api-key: <key>, which is what Anthropic clients send. If both are present, the Bearer value wins. The word Bearer is matched case-insensitively but must be followed by a space and the key.
Common causes
- The key field is empty in the client. In SillyTavern, switching the Chat Completion source clears which key slot is in use. The Custom (OpenAI-compatible) source has its own key field.
- An environment variable that never loaded. SDK code that reads
OPENAI_API_KEYfrom a.envfile sends nothing if the file was not loaded. - A hand-written header without "Bearer".
Authorization: sk-ww-...does not match the Bearer pattern, so no credential is found. - A proxy or browser extension that strips the header before it reaches the API.
Step by step fix
- Copy a key from /dashboard/. It starts with
sk-ww-. - In SillyTavern, set the source to Custom (OpenAI-compatible), paste the key into that source's API key field and press Connect.
- For code, pass the key explicitly while debugging, for example
OpenAI(base_url="https://wildwestapi.com/v1", api_key="sk-ww-..."), then move it back to an environment variable once it works. - For curl, test with the exact header:
curl https://wildwestapi.com/v1/chat/completions \
-H "Authorization: Bearer sk-ww-YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{"model":"outlaw-1","messages":[{"role":"user","content":"hi"}]}'Telling it apart from similar errors
A key that was sent but is wrong gives Invalid or disabled API key. instead; see 401 Unauthorized. A browser app that never got as far as sending the header is usually a CORS failure. More on keys in the API key glossary entry.
FAQ
Does the API accept the key as a query parameter?
No. It reads only the Authorization Bearer header or the x-api-key header.
I use an Anthropic client. Which header should I set?
Either works. Anthropic clients send x-api-key by default, and the API accepts it. If you also send Authorization: Bearer, that one is used.