{
  "id": 12646689,
  "title": "Sitecore Search API Key Authorization - How We* Tackled It",
  "url": "https://urgent.news/2026/10/07/sitecore-search-api-key-authorization-how-we-tackled-it",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T14:51:55.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/kmac23va/sitecore-search-api-key-authorization-how-we-tackled-it-lon"
  },
  "original_language": "en",
  "account": "Sitecore issued an email yesterday outlining a mandatory API key authorization for Search and Events APIs. Initially scheduled for mid-October 2026, the implementation has been moved to mid-December. The email prompted support to configure a non-production environment to test the rule enforcement. Our solution addressed the issue, as the Sitecore Search widget provider requires the Search customer key and API key in the NEXT_PUBLIC realm, exposing the API key. To mitigate this risk, we developed a new widget provider object that accepts the customer key and a generated, authorized API key instead. This approach enables us to maintain search authorization without exposing the raw API key. We collaborated with Claude Code, utilizing AI to create and test the solution in a Sitecore Search non-production environment. The solution involves a widget provider in the shared folder application/nextjs/src/components. It utilizes a placeholder API key during initialization, which is replaced with the authorized API key when the request middleware fetches a real access token from /api/search/accessToken. This method ensures a secure and efficient implementation of the Sitecore API key authorization.",
  "summary": "Sitecore sent out an email yesterday that was actually a \"kick the can\" email, regarding a mandatory API key authorization for Search and Events APIs. Originally, this was supposed to go live mid-October 2026, and now it'll be mid-December. The first email went out a month or two ago, and support offered to change a non-prod environment to enforce the rule for testing. So we went through all…",
  "key_points": [
    "Sitecore mandates API key authorization for Search and Events APIs, delayed to mid-December 2026.",
    "Non-production environment configured to test rule enforcement for Sitecore Search widget provider.",
    "New widget provider object developed to securely handle customer key and authorized API key."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}