# Authentication

> How to authenticate Kurrens API requests with an API key.

Every request must include your API key as a bearer token:

```http
Authorization: Bearer <KURRENS_API_KEY>
```

With the OpenAI SDKs, pass the key as `api_key` / `apiKey` and set the base URL to `https://api.kurrens.ai/v1`.

## Handling keys

- **Shown once.** A key is displayed only when it is created. Store it in a secret manager.
- **Server-side only.** Don't ship keys in browser, mobile, or desktop apps, and don't commit them to source control.
- **Rotate on suspicion.** If a key may have leaked, revoke it and issue a new one. Report suspected misuse to
  [support@kurrens.ai](mailto:support@kurrens.ai).
- **One key per environment.** Separate keys for development, staging, and production make rotation and usage tracking easier.

## Errors

| Status | Meaning |
|---|---|
| `401` | Missing, malformed, or revoked key |
| `403` | The key isn't allowed to use this model or feature |

See [Errors](/docs/getting-started/errors) for the full list.
