> ## Documentation Index
> Fetch the complete documentation index at: https://docs.influship.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> How to authenticate requests to the Influship API

Use an API key for direct server-side requests, OAuth for linked accounts, or a supported payment protocol for keyless requests.

| Before you start | Details |
| - | - |
| Auth | API key, OAuth, or payment protocol |
| Resource | Protected API operations |
| Cost | Authentication itself has no operation fee; see [Pricing](/concepts/pricing) |
| Limits | Keep credentials server-side; rotation is create, deploy, verify, revoke |

| Method | Credential | Setup |
| - | - | - |
| API key | `X-API-Key` header | Create a key in the [developer dashboard](https://developers.influship.com) |
| OAuth | `Authorization: Bearer <access_token>` | Complete account linking in your client; see [MCP setup](/guides/mcp-server) |
| x402 or MPP | Protocol payment headers | Follow [x402](/guides/x402) or [MPP](/guides/mpp) for supported paid endpoints |

Public health and discovery endpoints do not require an API key.

## Get your API key

Sign up at [developers.influship.com](https://developers.influship.com) and find your API key under **API Keys**. New API customers receive 500 one-time starter credits with no expiry; no card is required to use them. Each key uses the same account balance. See [Pricing](/concepts/pricing) for exhaustion and paid-billing behavior.

## Set it as an environment variable

```bash theme={null}
export INFLUSHIP_API_KEY="your_api_key_here"
```

Or add it to your `.env` file:

```bash .env theme={null}
INFLUSHIP_API_KEY="your_api_key_here"
```

<Warning>
  Never commit API keys to version control. Use environment variables or a secrets manager.
</Warning>

## Pass it in requests

<CodeGroup>
  ```typescript SDK theme={null}
  import Influship from 'influship';

  const client = new Influship({
    apiKey: process.env.INFLUSHIP_API_KEY,
    maxRetries: 0,
  });
  ```

  ```bash cURL theme={null}
  curl https://api.influship.com/v1/creators/autocomplete?q=travel \
    -H 'X-API-Key: YOUR_API_KEY'
  ```
</CodeGroup>

The SDK reads from the `INFLUSHIP_API_KEY` environment variable automatically, so you can also omit the constructor argument entirely if the variable is set.

## When authentication fails

An invalid or revoked API key returns `401 unauthorized`. An invalid OAuth token also returns `401`.

A request without credentials to a supported payment-enabled endpoint returns a `402` payment challenge. Follow the selected payment protocol rather than treating the challenge as an invalid key. Other protected endpoints require credentials.

A typical API-key failure looks like this:

```json theme={null}
{
  "error": {
    "code": "unauthorized",
    "message": "Invalid or missing API key",
    "status_code": 401
  }
}
```

If you receive this unexpectedly, check that the key is correctly set and has not been revoked.

## Key rotation

Creating another key does not revoke your existing keys. Rotate without interrupting traffic:

1. Create a new key in **API Keys** in the [dashboard](https://developers.influship.com).
2. Update your application's secret and deploy the new configuration.
3. Verify that requests using the new key succeed.
4. Revoke the old key after all callers have switched.

Revocation stops new requests using that key. Remove it from any remaining clients.

## Organization and billing

API keys share their account's starter-credit balance and billing settings. Creating another key does not add credits. API-key rate-limit windows are scoped to the key; OAuth calls use the linked credential's rate-limit scope. Monitor the returned headers rather than assuming keys have separate billing balances. See [Rate limits](/concepts/quotas-and-limits) and [Pricing](/concepts/pricing).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.