Instead of using a request body parameter to read the api key, we should use the `Authorization` header.