I\'m designing a public API to my company\'s data. We want application developers to sign up for an API key so that we can monitor use and overuse.
Since the API is
It should be put in the HTTP Authorization header. The spec is here https://tools.ietf.org/html/rfc7235