# Authentication

> Every request except GET /v1/health sends an API key as a Bearer token; keys belong to an account and share its wallet.

Send your API key in the `Authorization` header of every request:

```http
Authorization: Bearer mdw_live_<random characters>
```

- A key is `mdw_live_` followed by 32 lowercase characters (`a-z`, `2-7`). Only a hash is stored: the key is shown once, when you create it.
- Keys belong to your account, and credits belong to the account, not to a key. Revoking or replacing a key never changes your balance.
- An account can have up to 10 active keys. Create, rename and revoke them in the dashboard under [API keys](https://md.tlelabs.com/keys).
- `GET /v1/health` is the only endpoint without authentication.

## Rotating a key

Create a new key, switch your clients to it, then revoke the old one. A revoked key stops working on the next request. There are no refresh tokens.

## Failed authentication

Every authentication failure is status `401` with the code `invalid_api_key`. A missing or malformed header says so in the message; an unknown key, a revoked key and a suspended account all get the same response, so the API never reveals which case it was:

```json
{ "error": { "code": "invalid_api_key", "message": "Invalid API key." } }
```

The `/v1/*` endpoints accept only API keys: the dashboard’s sign-in session does not work there.

The API is meant to be called from servers. It sends no CORS headers, so browsers block calls from web pages, and a key in front-end code would be visible to anyone.
