API key
- Confirm the key is present in the runtime environment.
- Create a fresh key if rotation or copy-paste mistakes are possible.
- Check HTTP referrer, IP or app restrictions.
- Never paste API keys into public logs or support tickets.
Gemini API
A 401 or 403 means the request reached Google, but the credentials, project, API enablement, key restrictions, endpoint or permissions were not accepted.
Auth checklist