Higgsfield API key: how to get one and send it

A Higgsfield API key is a key ID plus a secret made in Higgsfield Console, sent together in one Authorization: Key header from server code only.

4 min readSume
All posts

A Higgsfield API key is a credential with two parts, a key ID and a secret, that you create in Higgsfield Console at console.higgsfield.ai. You send both in one header, Authorization: Key YOUR_KEY_ID:YOUR_KEY_SECRET, and only from server-side code.

Every Higgsfield fact below comes from Higgsfield's own API docs, read on 2026-09-28 and listed under Sources.

How do I get a Higgsfield API key?

Higgsfield's FAQ gives four steps:

  • Create an account at console.higgsfield.ai.
  • Generate your API credentials from the dashboard. Each credential is a key ID and a secret.
  • Follow Higgsfield's Quickstart for a first request.
  • Read How the API works, then call a generation endpoint available to your account.

How do I send the key with a request?

Requests go to https://api.higgsfield.ai. Put both parts in the Authorization header, joined by a colon, after the word Key. The FAQ says not to use a Bearer token. The legacy hf-api-key and hf-secret headers still work, but Higgsfield says new integrations should use Authorization.

From Higgsfield's Authentication, Client libraries and FAQ pages, read 2026-09-28.
ItemWhat the docs say
Where keys are madeHiggsfield Console
HeaderAuthorization: Key YOUR_KEY_ID:YOUR_KEY_SECRET
Legacy headershf-api-key and hf-secret, still accepted
Python SDKpip install higgsfield-client, then export HF_KEY="your-api-key-id:your-api-key-secret"
Node.js SDKnpm install @higgsfield/client, with HF_CREDENTIALS passed to config({ credentials })
Bad credentials401 Unauthorized with {"detail": "Invalid credentials"}
Model not open to your account404, 423 or 503, depending on the model's state
curl https://api.higgsfield.ai/requests/REQUEST_ID/status \
  --header "Authorization: Key ${HF_API_KEY_ID}:${HF_API_KEY_SECRET}"

What does using a Higgsfield API key cost?

Higgsfield charges per generation, not per key. The API is pay-as-you-go by default: you top up a balance, and successful requests are charged in account credits that expire a year after they are added (Sume vs Higgsfield compares the plans). Before you submit, the estimate endpoint returns the credits and US dollars for the same parameters on your account (Billing and retention).

  • Only successful requests are charged. Requests that end as failed or nsfw are not, and credits reserved for them are refunded automatically.
  • A queued request canceled before processing starts is refunded.
  • Rate limits depend on your account and the model; the Console dashboard shows them.

How do I keep a Higgsfield key safe?

Higgsfield says not to call the API from browser or mobile code, because anyone who inspects the app can extract the secret. Its v2 TypeScript client blocks browser use for the same reason. The docs also list these rules:

  • Store credentials in a secrets manager or encrypted environment variables.
  • Use separate credentials for development and production.
  • Never put credentials in URLs, logs, screenshots or support messages.
  • Rotate a credential immediately if it may have been exposed.

How is a Sume API key different?

A Sume key is one workspace-scoped value from the API Keys dashboard, sent as Authorization: Bearer or x-api-key, never both: a request with both is rejected with 401 unauthorized (Authentication). Sume vs Higgsfield compares the two platforms, and Higgsfield MCP server setup and cost covers Higgsfield's MCP route.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume