Skip to main content
Send your YingTu API key in the Authorization header on every request.
Never expose an API key in client-side code or public logs.
Use separate keys per environment and rotate any key that may have been disclosed.