---
title: 'API-key auth is no longer sent to another host on a redirect'
description: 'HTTP monitors now drop the api-key auth header when a redirect leaves the original origin, the same as they already did for Authorization.'
date: '2026-10-08'
category: 'improvement'
canonical_url: 'https://yorkermonitoring.com/changelog/2026-10-08-api-key-auth-redirects'
---

HTTP monitors that use `api-key` auth now remove that header when a
redirect points at a different origin (a different scheme, host or port).
Monitors using `basic` or `bearer` auth already behaved this way, because
the `Authorization` header has always been dropped on a cross-origin
redirect. An API key is just as much a credential, so it now gets the same
treatment.

**What might change for you.** If a monitor with `api-key` auth targets a
URL that redirects to another host, and that second host needs the key, the
monitor will start getting `401` or `403` from it. Point the monitor at the
final URL directly to fix it.

Nothing changes for redirects that stay on the same origin, or for monitors
with `followRedirects` off.

Headers you set yourself under `headers` are still forwarded on every
redirect, so keep credentials in `auth` rather than in a custom header. The
full rules are in the configuration reference under
[Redirects and credentials](/docs/reference/configuration#redirects-and-credentials).
