The API uses API key authentication. This guide explains how to obtain and use your API key.
Warning: API keys are sensitive credentials. Store them securely and never expose them in client-side code or public repositories.
Include your API key in the X-API-Key header of every request:
X-API-Key: your-api-key-here
curl -X POST https://api.b337.ai/api/session_ids \ -H "X-API-Key: your-api-key-here" \ -H "Content-Type: application/json"
The API key is missing, invalid, or expired.
{ "detail": "Invalid or missing API key" }
Solutions:
X-API-Key header is includedThe API key doesn't have permission for the requested operation.
{ "detail": "API key does not have permission for this operation" }
Solutions:
Every account gets an API key, so you can try the API before you subscribe.
Until your account has an active subscription, the API answers
403 No valid subscription. To get a sample response instead, add this
header to your request:
curl -X POST https://api.b337.ai/v3/place_bet \ -H "X-API-Key: YOUR_API_KEY" \ -H "X-Bet337-Sandbox: 1" \ -H "Content-Type: application/json" \ -d '{ ... }'
Every endpoint in these docs then returns an example with the same shape and status code as the real one, plus:
{ "sandbox": true, "sandbox_note": "Sample response: this API key has no active subscription. Subscribe to get live data." }
The response also carries the header X-Bet337-Sandbox: 1. A sample is never
real: no bet is placed, no balance is read and no session is started. Once
your subscription is active, the header is ignored and you get live data, so
you can leave it in your code.
To try any endpoint in these docs before you sign up, send the demo key
demo. It always returns the sample response, with no other header needed:
curl https://api.b337.ai/v3/events -H "X-API-Key: demo"
The demo key never reaches a real account. When you're ready for live data, create an account and use your own key.
You can test your API key by making a simple request:
curl -X POST https://api.b337.ai/api/session_ids \ -H "X-API-Key: YOUR_API_KEY" \ -H "Content-Type: application/json"
A successful response confirms your authentication is working:
{ "sessions": [ { "session_id": "uuid-string", "bookie": "tab", "username": "user@example.com", "active": true } ] }