# Authentication

## Bearer authentication

Send your key in the Authorization header on both submission and task queries:

```text
Authorization: Bearer YOUR_API_KEY
```

Create and revoke keys in [API keys](https://seedrouter.ai/apikeys). A new key is displayed in full only when created; save it securely at that point.

## Keep keys server-side

Read the key from an environment variable. Do not place it in browser code, public repositories, URLs, or screenshots. If a key is exposed, revoke it and create a replacement.

## Access to tasks

Task queries require a key belonging to the account that created the task. Knowing a task ID does not grant access to its result.

## Authentication errors

| Code    | Action                                              |
| ------- | --------------------------------------------------- |
| `10001` | Check that the key is present, correct, and active. |
| `10002` | Check the key's access permissions.                 |

See [Errors](https://seedrouter.ai/docs/api/errors) for the response shape.
