> ## Documentation Index
> Fetch the complete documentation index at: https://docs.denialbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> API keys for the claims API.

Every call carries your practice's API key as a bearer token:

```http theme={null}
Authorization: Bearer YOUR_API_KEY
```

## Create a key

An owner or admin of the practice creates keys in **Settings → API keys**, with the permissions the key needs:

| Permission | Scope | Lets the key |
| - | - | - |
| Send claims | `claims:write` | Call `POST /api/v1/claims`. |
| Read claim status | `claims:read` | Call `GET /api/v1/claims/status`. |

The key is shown **once**, when you create it. Copy it into your server's secret storage right away. If it's lost,
revoke it and create a new one.

## Keep it on your server

The key acts for your whole practice. Use it only from your own server:

* Never put it in a web page, a mobile app or a browser script. The API is server to server and doesn't answer
  browser (CORS) requests.
* Never commit it to source control.

## Expiry, revocation and rotation

* Keys expire **one year** after they're created.
* Revoke a key any time in **Settings → API keys**; it stops working right away.
* To rotate, create the new key, switch your system over, then revoke the old one.

A missing, unknown, revoked or expired key gets `401`. A key without the scope an endpoint needs gets `403`. See
[Errors](/api-reference/errors).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.