> ## Documentation Index
> Fetch the complete documentation index at: https://docs.anyformat.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate your API requests using API keys

## Getting Your API Key

1. Log in to your [anyformat account](https://app.anyformat.ai).
2. Open the [API Key page](https://app.anyformat.ai/api-key), generate a key, and **copy it**. The page shows a key once.

## Authentication Method

Use your API key in the `Authorization` header with Bearer format:

```bash theme={null}
Authorization: Bearer YOUR_API_KEY
```

## Using Your API Key

Send your API key in the headers of every request:

<CodeGroup>
  ```bash curl theme={null}
  curl "https://api.anyformat.ai/v3/workflows/" \
       -H "Authorization: Bearer YOUR_API_KEY"
  ```

  ```python Python (SDK) theme={null}
  import os
  from anyformat.sdk import Client

  # Pass explicitly
  client = Client(api_key="your_api_key_here")

  # Or read from the environment
  client = Client(api_key=os.environ["ANYFORMAT_API_KEY"])
  ```

  ```python Python (requests) theme={null}
  import requests

  headers = {
      "Authorization": "Bearer YOUR_API_KEY"
  }

  response = requests.get(
      "https://api.anyformat.ai/v3/workflows/",
      headers=headers
  )
  ```

  ```javascript JavaScript theme={null}
  const response = await fetch('https://api.anyformat.ai/v3/workflows/', {
    method: 'GET',
    headers: {
      'Authorization': 'Bearer YOUR_API_KEY'
    }
  });

  const data = await response.json();
  ```

  ```java Java theme={null}
  import java.net.http.HttpClient;
  import java.net.http.HttpRequest;
  import java.net.http.HttpResponse;
  import java.net.URI;

  HttpClient client = HttpClient.newHttpClient();
  HttpRequest request = HttpRequest.newBuilder()
      .uri(URI.create("https://api.anyformat.ai/v3/workflows/"))
      .header("Authorization", "Bearer YOUR_API_KEY")
      .GET()
      .build();

  HttpResponse<String> response = client.send(request,
      HttpResponse.BodyHandlers.ofString());
  ```

  ```go Go theme={null}
  package main

  import (
      "net/http"
  )

  func main() {
      client := &http.Client{}
      req, _ := http.NewRequest("GET", "https://api.anyformat.ai/v3/workflows/", nil)
      req.Header.Add("Authorization", "Bearer YOUR_API_KEY")

      resp, _ := client.Do(req)
  }
  ```

  ```rust Rust theme={null}
  use reqwest;

  fn main() {
      let client = reqwest::blocking::Client::new();
      let response = client.get("https://api.anyformat.ai/v3/workflows/")
          .header("Authorization", "Bearer YOUR_API_KEY")
          .send()
          .unwrap();

      println!("{}", response.text().unwrap());
  }
  ```
</CodeGroup>

<Note>
  The API accepts the `Authorization` header in any casing, such as `authorization` or `AUTHORIZATION`. The HTTP specification makes header names case-insensitive.
</Note>

## Verifying a Key

Call [`GET /key-check/`](/api-reference-v3/key-check) to confirm a key is active before your first real request. On success it returns `200` with the owning organization. Otherwise it returns the standard `401` error envelope, with `error_code` `MISSING_API_KEY` or `INVALID_API_KEY`. The call bills nothing and creates no run.

## API Key Scoping

Each API key belongs to one organization. Every request made with that key operates inside that organization's data, so it reaches only that organization's workflows, document packets and runs.

* A user who belongs to several organizations needs one API key per organization.
* Generating a new API key revokes the previous key for the same organization.
* An API key grants the same access level as the user who created it. Keys carry no granular scopes and no permission restrictions.

<Note>
  API keys are managed in the [anyformat platform](https://app.anyformat.ai/api-key). The API does not expose key management endpoints.
</Note>

## Public Endpoints

These endpoints need no API key:

* `/`, the API root
* `/health/`, the health check
* `/schema/`, the OpenAPI schema
* `/docs/`, the Swagger UI documentation

## Revoking a Key

<Card title="Generate a new key to automatically revoke the old one." icon="key" href="https://app.anyformat.ai/api-key" />

## Security Best Practices

1. **Never share your API key.** Treat it like a password.
2. **Rotate keys on a schedule.** Generate a new key regularly.
3. **Use environment variables.** Store keys in the environment in production.
4. **Monitor key usage.** Watch your account for suspicious activity.
5. **Never expose a key in client-side code.** Use an API key server-side only.

<Note>
  If you suspect a key is compromised, open the [API Key page](https://app.anyformat.ai/api-key) at once and generate a new one.
</Note>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.