> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pointzero.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate PointZero API requests with a secret bearer key, tell sandbox and live keys apart, and keep your keys off client devices.

Send your secret key in the `Authorization` header of every request:

```bash theme={null}
curl https://api.pointzero.io/v1/cards \
  -H "Authorization: Bearer sk_live_..."
```

| Prefix | Environment |
| - | - |
| `sk_test_` | Sandbox |
| `sk_live_` | Production |

Create and revoke keys in the [Dashboard](https://dashboard.pointzero.io).

<Warning>
  Secret keys give full access to your account. Use them only on your server. Never put them in mobile apps, browser code or public repositories.
</Warning>

A missing or invalid key returns `401`. A valid key without access to the resource returns `403`.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.