CCAO-F Using the Claude API Practice Question
A developer is writing code that calls the Anthropic Messages API and needs to authenticate each request. The developer has retrieved the API key from a secure secret manager at runtime. Where should the API key be placed in the HTTP request?
⚠ Common exam trap
The trap here is assuming the API uses the generic Authorization header or a body field, when it specifically requires the x-api-key header.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the 'x-api-key' HTTP header on each request.
Direct HTTP calls to the Anthropic Messages API authenticate by including the API key in the x-api-key request header. This keeps the credential out of URLs and payloads, which is important for security and log hygiene. Body fields, query parameters, and Basic authentication schemes are not recognized by the API for this purpose, so requests using them will fail authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
In the URL as a query parameter such as ?api_key=sk-ant-...
Why it's wrong here
Passing credentials as URL query parameters is not supported by the Messages API for authentication and exposes the key in server logs, proxies, and browser history. This is a well-known security anti-pattern. The API expects the key in a header, so this approach will result in an authentication failure while also leaking the secret.
- ✗
In the request body as a top-level 'api_key' field alongside 'model' and 'messages'.
Why it's wrong here
The Messages API does not accept an api_key field in the JSON body; including one will not authenticate the request and may cause a validation error. Authentication is handled through HTTP headers, not payload fields. Placing the key in the body also risks it being logged with request contents, which is a security concern in addition to being functionally incorrect.
- ✗
In the 'Authorization' header using the scheme 'Basic' with the key base64-encoded.
Why it's wrong here
The Messages API does not use HTTP Basic authentication with a base64-encoded key. While an Authorization header is common for other services, this API expects the key in x-api-key. Using Basic auth here will fail authentication because the server is not looking for credentials in that header or scheme, so the request will be rejected.
- ✓
In the 'x-api-key' HTTP header on each request.
Why this is correct
The Anthropic Messages API authenticates requests using the x-api-key header, and the value is the API key retrieved from the secret manager. This keeps the credential out of the URL and the JSON body, reducing leakage risk. Sending it this way on every request is the documented and expected authentication method for direct HTTP integrations with the API.
About these practice questions
One of 259 original CCAO-F practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAO-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAO-F exam.