credentials_in_url
- HTTP status
- 400 Bad Request
- Returned by
- Sign-in and authentication
What it means
The request put a credential in the query string (?api_key= or ?access_token=). Kweko refuses it so keys never end up in logs and browser history.
Typical causes
- A client library or a no-code tool was configured to pass the key as a URL parameter.
How to fix it
- Send the key in the
Authorization: Bearerheader instead, and rotate the key: it may already be in someone's logs.
Message
English text, as sent with Accept-Language: en. With ru or uz the API sends the translation.
- Send API keys in the Authorization header, never in the URL.
RU: Передавайте API-ключи в заголовке Authorization, а не в URL.
UZ: API kalitlarni URL da emas, Authorization sarlavhasida yuboring.
Example response
Response
HTTP/1.1 400 Bad Request
Content-Type: application/json; charset=utf-8
X-Request-Id: req_4f2a9c1e0b7d3a55
{
"error": {
"code": "credentials_in_url",
"message": "Send API keys in the Authorization header, never in the URL.",
"request_id": "req_4f2a9c1e0b7d3a55",
"docs_url": "https://developers.kweko.uz/errors/credentials_in_url"
}
}