Send your API key in a header. Never in the query string.
| API Key | Label | Last Used | |
|---|---|---|---|
Every call authenticates with an API key issued by the hotel.
X-API-Key: axis_live_…
Authorization: Bearer axis_live_… is accepted as an alternative transport for
the same key.
A key in the query string is never accepted — it would end up in access logs,
browser history and referrer headers.
The key is the account
You never send an account identifier. The key resolves it.
X-Property is different: send it only when your key covers more than one
property. A key scoped to exactly one infers it, and sending a different id
answers 404. See
Scopes and the X-Property header.
When it fails
An unknown, expired, revoked or deactivated key all answer the same
401 APIKEY_INVALID. Distinguishing them would tell an attacker which guesses
are close.
Two failures do get their own code, because they are actionable: APIKEY_MISSING
(a wiring mistake) and TENANT_INACTIVE (an account state the hotel can fix).
A valid key missing a scope answers 403 APIKEY_SCOPE_MISSING, and the message
names the scope — the one place we are deliberately more helpful, because the
caller has already proved who they are.
Full detail in Authentication and API keys.