Home → Help
401 Unauthorized with a key you just copiedinvalid_api_key / authentication_errorcurl works but the app does not, with the same keyThe key works in one client and not anotherSome HTTP clients and no-code tools ask for a 'token' and add the Bearer prefix themselves. Pasting 'Bearer sk-...' into such a field produces 'Bearer Bearer sk-...'.
Copying from a chat window or a PDF can bring a trailing newline or a non-breaking space. The string looks identical on screen and is not identical on the wire.
A few gateways accept an x-api-key header instead, or in addition. Sending the key in the wrong header is indistinguishable from not sending it at all.
Print exactly what your client is sending, with the key length visible:
KEY='paste-here'
echo "length: ${#KEY}"
curl -s -o /dev/null -w '%{http_code}\n' \
'YOUR_BASE_URL/models' -H "Authorization: Bearer $KEY"
If the length is not what you expect, the copy is the problem. A 200 here with a 401 in your app means the app is building the header differently — inspect what it sends, not what you pasted.
sk- and go in Authorization: Bearer <key>. A key belongs to one group, so a key that authenticates fine can still 404 on a model outside its group — that is a different error with a different fix.Last checked 2026-10-01. Written from problems diagnosed on a live OpenAI-compatible gateway, not collected from other sites.