Every request to the Elite Prospects API must include an API key. You can send it in one of two ways:
- The
X-Api-Key request header. This is the recommended way.
- The
apiKey query parameter.
Obtaining a key
Apply for an API key on the Elite Prospects developer portal. Keys are issued per organisation. For questions, contact [email protected].
Using the key
Send the key in the X-Api-Key header on every request:
Query parameter
The apiKey query parameter also works:
If you send both, the API uses the header. An empty header counts as no header, so the API falls back to the query parameter.
If you send the key in the header, the URLs the API returns never include it. This covers every _links entry and redirects. When you follow one of these links, send the X-Api-Key header again.
If you authenticate with the query parameter, the returned links include apiKey. You can follow them as they are.
Keeping your key safe
A key in a URL ends up in access logs, browser history and proxy logs. Use the X-Api-Key header to keep it out of URLs. If you use the query parameter, treat every request URL as sensitive. Don’t share those URLs in support tickets or commit them to repositories.
- Store the key in a server-side environment variable or secret manager.
- Make API calls from your backend, not directly from a browser or mobile client.
- Rotate the key if you suspect it has been exposed (contact [email protected]).
What your key unlocks
Your subscription controls which regions, leagues, seasons, and data categories your key can see. For a breakdown of those scopes, see Coverage.
Authentication errors