# Authentication

> Send your API key as a bearer token or in x-api-key.

Every endpoint except `GET /v1/models` and `GET /v1/models/{id}` needs a key. Keys start with `sk-df-`.

## Send the key

Either header works on every endpoint.

**Authorization**

```bash
curl https://deference.si/v1/key \
  -H "Authorization: Bearer sk-df-..."
```

**x-api-key**

```bash
curl https://deference.si/v1/key \
  -H "x-api-key: sk-df-..."
```

OpenAI's SDKs send `Authorization`. Anthropic's SDKs send `x-api-key`. Claude Code sends the token as `Authorization` when you set `ANTHROPIC_AUTH_TOKEN`.

## Base URLs

| Client                         | Base URL                  |
| ------------------------------ | ------------------------- |
| OpenAI SDKs and most tools     | `https://deference.si/v1` |
| Anthropic SDKs and Claude Code | `https://deference.si`    |

## Keys

Create keys in [API keys](https://deference.si/keys). A key is shown once. Each key can have a credit limit and an expiry. See [Keys and security](https://deference.si/docs/dashboard/keys-and-security).

## Failures

| Status | Code               | Cause                     |
| ------ | ------------------ | ------------------------- |
| 401    | `missing_api_key`  | No key in the request     |
| 401    | `invalid_api_key`  | The key is not recognized |
| 401    | `api_key_disabled` | The key is disabled       |
| 401    | `api_key_expired`  | The key has expired       |

A request rejected for its key does not appear in [Activity](https://deference.si/docs/dashboard/activity).

## Keep keys secret

Call the API from a server. A key in client-side code can be read and spent by anyone.
