Skip to main content
Every request, /healthz included, carries your key:
A missing, unknown or revoked key answers 401:
  • The key is yours alone. Nomos sees every request it makes. If it leaks, tell Nomos: it can be revoked at once and replaced.
  • Server side only. The API sends no CORS headers, so browsers cannot call it directly, and a key in browser code would be public anyway. Call it from a server, a script or a notebook.
  • One key, every route in this reference.
The playground on each endpoint page sends your key through Mintlify’s request proxy. To keep a key off third-party servers entirely, use cURL or your own code.