Authentication
All public OpenInfra Solana services require the API key created from your project dashboard.
API key format
Gateway-issued production keys use the sk_live_ prefix. Treat the complete value as a secret; the prefix does not grant a separate scope or network.
Authentication by service
| Service | Credential location |
|---|---|
| Solana RPC | x-api-key (preferred) or ?api-key= |
| WebSocket | x-api-key or ?api-key= |
| Yellowstone gRPC | x-token metadata |
| Datastream | x-api-key metadata |
| Eventstream | x-api-key metadata |
RPC header
curl https://rpc.sol.openinfra.sh \ -H "content-type: application/json" \ -H "x-api-key: $OPENINFRA_API_KEY" \ -d '{"jsonrpc":"2.0","id":1,"method":"getHealth"}'Query parameter
Use the query form only when the client cannot set connection headers, such as the browser WebSocket constructor.
https://rpc.sol.openinfra.sh?api-key=YOUR_API_KEYwss://ws.sol.openinfra.sh?api-key=YOUR_API_KEYShredStream access
ShredStream has no public endpoint and is not authenticated with your project API key. Delivery is authorized by the per-server selection in your project dashboard and sent over the isolated private network to the assigned 10.250.0.x address on UDP port20001.
Failure behavior
- Missing credentials return
HTTP 401for HTTP services or an unauthenticated gRPC status. - Invalid credentials return
HTTP 401for RPC. Authorization: Beareris not a supported replacement forx-api-key.- TLS is required on all published endpoints.
Rotating a key
Create a replacement key, update every consumer, verify traffic with the new key, and only then revoke the old key. Revocation invalidates future requests using that credential.