# Authentication

Source: https://platform.msingiai.com/docs?page=auth

API base URL: https://api.msingiai.com

There are two separate credentials in this system. Using the wrong one for a given call returns 401.

## API keys: for /v1/audio/*, /v1/models and /v1/voices

Create keys under API keys in the dashboard. Send them as Authorization: Bearer msk_... (or the X-Api-Key header) from your own trusted server. A key's permission preset (tts_stt / tts_only / stt_only) controls which operations it can call.

## Dashboard session: everything else

The dashboard itself (organizations, projects, keys, usage, billing) is authenticated by your browser session after signing in. You never handle that token directly.

## Rotation

Create a replacement key, deploy it, confirm traffic, then revoke the old key from API keys. Both work until you revoke the old one.

## Header format

### Bash / cURL

```bash
curl "$MSINGI_BASE_URL/v1/models" \
  -H "Authorization: Bearer $MSINGI_API_KEY"
```

### Python

```python
headers = {"Authorization": f"Bearer {API_KEY}"}
```

### JavaScript / Node.js

```javascript
const headers = { Authorization: `Bearer ${API_KEY}` };
```

Create a key for your server integration.

[Go to API keys](https://platform.msingiai.com/keys)

[Documentation index](https://platform.msingiai.com/llms.txt)
