# API Authentication

> Create API keys and authenticate requests with a Bearer token.

Source: https://xbeast.io/docs/api-authentication

Every Public API request must include an API key in the `Authorization` header. Keys start with `xb_live_` and are hashed at rest. The full key is shown only when you create it.

> **Treat keys like passwords**
>
> Anyone with the key can schedule and publish as your connected accounts. Revoke leaked keys immediately.

## Create a key

1. Open https://xbeast.io/developers while logged in.
2. Use a paid XBeast plan (free accounts cannot create keys).
3. Name the key (for example Production) and click Create key.
4. Copy the secret. You will not see it again.

You can have up to 5 active keys. Revoke unused keys from the same page.

## Request header

```http
Authorization: Bearer xb_live_YOUR_KEY
```

**Example**

```bash
curl "https://xbeast.io/api/v1/credits" \
  -H "Authorization: Bearer xb_live_YOUR_KEY"
```

## Rules

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| Scheme | Bearer | Yes | Only Bearer tokens are accepted. Cookie session auth is not used on /api/v1. |
| Prefix | string | Yes | Keys must start with xb_live_. |
| Plan | paid | Yes | Free plans receive 403 forbidden even with a valid-looking header. |

## Failed auth

Missing, malformed, revoked, or unknown keys return `401` with `error.code: unauthorized`. See [Errors](https://xbeast.io/docs/api-errors.md).

[List accounts](https://xbeast.io/docs/api-accounts.md)
