Higgsfield API key: how to get one and send it
A Higgsfield API key is a key ID plus a secret made in Higgsfield Console, sent together in one Authorization: Key header from server code only.

A Higgsfield API key is a credential with two parts, a key ID and a secret, that you create in Higgsfield Console at console.higgsfield.ai. You send both in one header, Authorization: Key YOUR_KEY_ID:YOUR_KEY_SECRET, and only from server-side code.
Every Higgsfield fact below comes from Higgsfield's own API docs, read on 2026-09-28 and listed under Sources.
How do I get a Higgsfield API key?
Higgsfield's FAQ gives four steps:
- Create an account at console.higgsfield.ai.
- Generate your API credentials from the dashboard. Each credential is a key ID and a secret.
- Follow Higgsfield's Quickstart for a first request.
- Read How the API works, then call a generation endpoint available to your account.
How do I send the key with a request?
Requests go to https://api.higgsfield.ai. Put both parts in the Authorization header, joined by a colon, after the word Key. The FAQ says not to use a Bearer token. The legacy hf-api-key and hf-secret headers still work, but Higgsfield says new integrations should use Authorization.
| Item | What the docs say |
|---|---|
| Where keys are made | Higgsfield Console |
| Header | Authorization: Key YOUR_KEY_ID:YOUR_KEY_SECRET |
| Legacy headers | hf-api-key and hf-secret, still accepted |
| Python SDK | pip install higgsfield-client, then export HF_KEY="your-api-key-id:your-api-key-secret" |
| Node.js SDK | npm install @higgsfield/client, with HF_CREDENTIALS passed to config({ credentials }) |
| Bad credentials | 401 Unauthorized with {"detail": "Invalid credentials"} |
| Model not open to your account | 404, 423 or 503, depending on the model's state |
curl https://api.higgsfield.ai/requests/REQUEST_ID/status \
--header "Authorization: Key ${HF_API_KEY_ID}:${HF_API_KEY_SECRET}"What does using a Higgsfield API key cost?
Higgsfield charges per generation, not per key. The API is pay-as-you-go by default: you top up a balance, and successful requests are charged in account credits that expire a year after they are added (Sume vs Higgsfield compares the plans). Before you submit, the estimate endpoint returns the credits and US dollars for the same parameters on your account (Billing and retention).
- Only successful requests are charged. Requests that end as
failedornsfware not, and credits reserved for them are refunded automatically. - A queued request canceled before processing starts is refunded.
- Rate limits depend on your account and the model; the Console dashboard shows them.
How do I keep a Higgsfield key safe?
Higgsfield says not to call the API from browser or mobile code, because anyone who inspects the app can extract the secret. Its v2 TypeScript client blocks browser use for the same reason. The docs also list these rules:
- Store credentials in a secrets manager or encrypted environment variables.
- Use separate credentials for development and production.
- Never put credentials in URLs, logs, screenshots or support messages.
- Rotate a credential immediately if it may have been exposed.
How is a Sume API key different?
A Sume key is one workspace-scoped value from the API Keys dashboard, sent as Authorization: Bearer or x-api-key, never both: a request with both is rejected with 401 unauthorized (Authentication). Sume vs Higgsfield compares the two platforms, and Higgsfield MCP server setup and cost covers Higgsfield's MCP route.
Sources
Related posts
More in Developers
- HMAC vs digital signature: what each proves for webhooks
An HMAC proves the sender holds a shared secret. A digital signature is made with a private key and checked with a public one, adding non-repudiation.
- How long does it take to generate an AI image?
On Sume, most AI images finish inside the 30 seconds the API holds a request open. What makes one take longer, and how to tell slow from stuck.
- How to build your own AI video generator (no training)
Build your own AI video generator from a front end, a small backend and a video model API. You don't train a model; your backend holds the key.
- How to get a Kling AI API key and authenticate requests
Create a Kling AI API key in the developer console, copy it once, and send it as a Bearer token. Legacy endpoints use an Access Key JWT instead.
Written by Sume