# Authentication

> Authenticate your API requests using API keys

- Page: https://tbit.app/docs/api/authentication
- Base URL: `https://rest-api.tbit.app/v1`
- Authentication: `X-API-Key` header with your key on every request (the examples read it from the `TBIT_API_KEY` environment variable)

## Overview

The TBit API uses API keys for authentication. Include your API key in the X-API-Key header with every request.

## Getting Your API Key

Navigate to Settings > API in the TBit dashboard to reveal your API key. Each agent has a unique API key.

## Usage

Include the X-API-Key header in every request:

`GET /v1/activities`

```bash
curl "https://rest-api.tbit.app/v1/activities" \
  -H "X-API-Key: $TBIT_API_KEY"
```

## Security Best Practices

- Never expose your API key in client-side code or public repositories
- Use environment variables to store your API key
- Rotate your API key if you suspect it has been compromised
- Only use HTTPS when making API requests

## Publishable Usage for Catalog Endpoints

Exception: for catalog read endpoints (products, categories, carts) the API key acts like a publishable key: it identifies your tenant and meters usage, and catalog data is public. It is safe to use from browser code for those endpoints, just like a Stripe publishable key.

## Authentication Errors

| Status | Code | Description |
| --- | --- | --- |
| `401` | `UNAUTHORIZED` | Missing or invalid API key |
| `429` | `RATE_LIMITED` | Rate limit exceeded (100 req/min) |
