Is this error coming from 9Coding?
- Check the address and the request id first: when a request to
api.9coding.comis rejected by 9Coding itself (an invalid key, for example),messageends with(request id: …). An error that carries another service's markers (see step 2) is not from 9Coding. Missing x-bb-api-key headercomes from the cloud browser service Browserbase: configure that service's own key (BROWSERBASE_API_KEY) and do not put a 9Coding key there.- A 9Coding key is only for
https://api.9coding.com: OpenAI-compatible clients sendAuthorization: Bearer; Claude Code usesANTHROPIC_BASE_URLandANTHROPIC_AUTH_TOKEN.
A single toolchain often calls several services at once: a model gateway, a cloud browser, code hosting, search. Their errors all land in the same terminal or chat window and look alike — they all read as "authentication failed". Before checking keys, establish which service returned the error: a different source means a different key and a different configuration to check.
Errors to identify
{
"statusCode": 401,
"error": "Unauthorized",
"message": "Missing x-bb-api-key header"
}
{
"error": {
"message": "Incorrect API key provided: sk-9c-ab…wxyz. You can find your API key at https://platform.openai.com/account/api-keys.",
"type": "invalid_request_error",
"param": null,
"code": "invalid_api_key"
}
}
{
"error": {
"code": 400,
"message": "API key not valid. Please pass a valid API key.",
"status": "INVALID_ARGUMENT",
"details": [{
"@type": "type.googleapis.com/google.rpc.ErrorInfo",
"reason": "API_KEY_INVALID",
…
}]
}
}
All three are about authentication, and none of them came from 9Coding: the first is from Browserbase, the second from the official OpenAI API, the third from Google's Gemini API. The steps below show how to tell. JSON examples on this page are laid out one field per line, and … marks omitted text.
Work through it in this order
1 · Check the address and the request id#
9Coding exposes two APIs, and their error formats differ. Only a request sent to one of these two addresses can get an error returned by 9Coding.
Inference gateway · api.9coding.com: serves every model call, including OpenAI-compatible endpoints such as /v1/chat/completions and the /v1/messages endpoint that Claude Code uses. A missing or invalid key returns:
{
"error": {
"code": "",
"message": "Invalid token (request id: 2026…)",
"type": "new_api_error"
}
}
How to recognise it: the request went to api.9coding.com and message ends with (request id: …); for a missing or invalid key, type is new_api_error. The request id starts with a UTC timestamp (such as 2026…; Beijing time is 8 hours ahead), and the gateway's x-oneapi-request-id response header carries the same id, visible with curl -i. Some errors, such as upstream errors that 9Coding forwards, may not carry a request id in message. Other relays running the same open-source gateway return the same format, so the address is what decides.
Console API · 9coding.com/api: serves the website and console, including sign-in, key management, top-ups and usage. Model calls never go through it. A request without a valid sign-in returns:
{
"message": "missing bearer token",
"success": false
}
How to recognise it: message and success side by side, with success set to false. These errors appear in requests made by the website and console (for example, in the Network panel of the browser's developer tools) and are unrelated to model calls; when the sign-in has expired, signing in to the console again resolves it.
2 · Compare with known third-party errors#
Only formats distinctive enough to identify the source with confidence are listed.
- Browserbase:
Missing x-bb-api-key header
Signs:statusCode,errorandmessagesit side by side;x-bb-api-keyis the auth header of Browserbase, a cloud browser service.
Fix: configure Browserbase's own key — see below. - OpenAI API:
Incorrect API key provided
Signs: points toplatform.openai.com;codeisinvalid_api_key.
Fix: the request went straight to the official OpenAI API; set the base URL tohttps://api.9coding.com/v1. - Anthropic API:
"request_id":"req_…"
Signs: a top-levelrequest_idfield starting withreq_; no(request id: …)at the end ofmessage.
Fix: the request went straight to the official Anthropic API and bypassed 9Coding; check thatANTHROPIC_BASE_URLis in effect. - Google API:
API key not valid
Signs: an error from an official Google API (such as the Gemini API) with"status":"INVALID_ARGUMENT"and areasonofAPI_KEY_INVALIDindetails.
Fix: the request went straight to Google, so find the tool that sent it. For Gemini CLI, setGOOGLE_GEMINI_BASE_URLas in the Gemini guide; other tools that call Google directly (such as the Browserbase MCP server — see below) need a Google key. - The client:
Could not resolve authentication method
Signs: the client failed before sending the request; there is no HTTP response.
Fix: setANTHROPIC_AUTH_TOKEN— see 401 Unauthorized. - Local machine or network:
ECONNREFUSED·ENOTFOUND·ETIMEDOUT
Signs: no status code and no response body.
Fix: see Connection error.
If the key went to a third party: in the OpenAI, Anthropic and Google cases, if the request carried a 9Coding key (for example, the key echoed in OpenAI's error starts with sk-9c-), that key has been sent to the other service. After fixing the address, delete the key in the 9Coding console and create a new one.
3 · Confirm the 9Coding side with one curl request#
The example uses the Claude Code variable. Use the key that the failing tool is actually configured with; for other clients, replace the variable with the key entered in that tool.
curl -s https://api.9coding.com/v1/models \
-H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN"
curl.exe -s https://api.9coding.com/v1/models `
-H "Authorization: Bearer $env:ANTHROPIC_AUTH_TOKEN"
- A model list comes back → this key and address are valid. If the original error carries
(request id: …), or is a model-not-found, rate-limit, balance or context-length error, it still came from 9Coding; look up the matching page in the troubleshooting index. If the original error is an authentication error without 9Coding's markers, it came from another service in the toolchain; use step 2 to find which. - An error with
(request id: …)comes back → it came from 9Coding.Invalid tokenmeans the key is invalid or no key was sent (an empty variable gives the same result) — see 401 Unauthorized; for anything else, look up the matching page in the troubleshooting index. - No output at all → curl got no response; this is a network problem — see Connection error.
Missing x-bb-api-key header · from Browserbase
{
"statusCode": 401,
"error": "Unauthorized",
"message": "Missing x-bb-api-key header"
}
Cause: the request reached Browserbase, a cloud browser service, without that service's key. x-bb-api-key is the Browserbase API's authentication header (written X-BB-API-Key in its documentation). 9Coding authentication does not use this header and does not issue keys for it.
Where it shows up: the official Browserbase MCP server, and Stagehand running in the Browserbase environment, both start cloud browsers through this API. When such a component is added to Claude Code, Cursor or a similar tool without a Browserbase key, the step that opens a browser is rejected by Browserbase. The model call and the browser call are two separate requests: the first goes to 9Coding, the second to Browserbase, and this error comes only from the second.
Fix: get an API key from the Browserbase dashboard and configure it as the component's documentation describes. The Browserbase MCP server and Stagehand read the BROWSERBASE_API_KEY environment variable:
export BROWSERBASE_API_KEY="<key from the Browserbase dashboard>"
For the MCP server run locally (npx @browserbasehq/mcp), the key goes in the env block of that server's configuration; for the MCP server hosted by Browserbase (mcp.browserbase.com), the key goes in the browserbaseApiKey parameter of its URL. Restart the tool afterwards: Claude Code reads environment variables only once, at startup.
The model key is separate too: by default the Browserbase MCP server uses Google's Gemini model and also needs GEMINI_API_KEY; those calls go straight to Google, not through 9Coding. Use a Google AI Studio key here, not a 9Coding key. If GEMINI_API_KEY is already set system-wide to a 9Coding key, as in the Gemini guide, set the Google key explicitly in the env block of the MCP server's configuration so the system-wide value is not used.
Do not put a 9Coding key into x-bb-api-key or BROWSERBASE_API_KEY. Browserbase cannot authenticate with it, and doing so sends a 9Coding key to a third-party service. If that has already happened, delete the key in the 9Coding console and create a new one.
The correct way to authenticate with 9Coding
9Coding API keys (in the form sk-9c-…) are created on the API Keys page of the console. Every model call goes to https://api.9coding.com; configure each client as follows:
# OpenAI-compatible SDK · curl
base URL: https://api.9coding.com/v1
Authorization: Bearer <key>
# Claude Code
ANTHROPIC_BASE_URL=https://api.9coding.com
ANTHROPIC_AUTH_TOKEN=<key>
# Gemini CLI
GOOGLE_GEMINI_BASE_URL=https://api.9coding.com
GEMINI_API_KEY=<key>
Full steps are in the OpenAI SDK, Claude Code and Gemini guides. 9Coding authentication does not use x-bb-api-key, and 9Coding does not issue or hold keys for non-model services such as Browserbase. Each service in the toolchain needs its own key.
What to send to support
request id; ② the endpoint that was called, for example /v1/chat/completions or /v1/messages on api.9coding.com; ③ the tool or client name and version, for example Claude Code, Cursor or a custom program; ④ the time with its time zone, and the model name.Never send the API key. Troubleshooting does not need it. Remove or mask any key or token that appears in a screenshot, log or URL (for example a
?key= query string) first; if a key has leaked, delete it in the console and create a new one.
An error that did not come from 9Coding has no matching entry in 9Coding's call records; report it to the service that returned it.
Related errors
- 401 Unauthorized — authentication errors returned by 9Coding
- Connection error — telling the network, a proxy and the endpoint apart
- All errors — the full troubleshooting index