# Authentication

> The x-api-key header, and how to get a key today.

Source: https://docs.toolzerhub.com/docs/authentication

## The header
Every request to `api.toolzerhub.com` is authenticated with a single header:

```
x-api-key: <your-api-key>
```

```bash
curl "https://api.toolzerhub.com/v1/credits" \
  -H "x-api-key: $TOOLZERHUB_API_KEY"
```

The same API key authenticates every endpoint documented in the
[API reference](/reference). Some endpoints also require source-specific
query or body values; those are documented on the endpoint page.

A request without a valid key, or with a key that's been revoked, gets back
an `UNAUTHORIZED` or `FORBIDDEN` error — see
[Responses & Errors](/docs/responses-and-errors) for the exact shape.

<Callout title="Keep your key server-side" type="warn">
  Treat `x-api-key` like any other secret credential. Call the API from your
  backend, not from client-side code where the key would be exposed to end
  users.
</Callout>

## Getting a key
<Callout title="Create an API key" type="info">
  Sign up at
  [app.toolzerhub.com/signup](https://app.toolzerhub.com/signup), then use the
  key from your account when calling the API.
</Callout>

Sign up at &#x2A;*[app.toolzerhub.com/signup](https://app.toolzerhub.com/signup)**.
That's the product dashboard, not this documentation subdomain — this site
(`docs.toolzerhub.com`) is reference material only, it doesn't issue or
manage keys itself.
