> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nesu.pt/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Create and manage your API keys and authenticate requests with a bearer token.

## Prerequisites

You need a Nesu account to create an API key. Sign in to your Nesu dashboard and open **Chaves de API** (`/app/api-keys` in the Nesu application).

## Create your key

1. If your account has a newly activated key, copy the full secret displayed on the page. Otherwise, select **Criar chave de API**, enter a name, and create your key.
2. Save the secret when it appears. You cannot retrieve the full key again after you dismiss it or leave the page.
3. Store it in your server's environment or secret store.

Your full key begins with `nesu_`. The truncated prefix shown in the key list is not sufficient to authenticate a request.

## Authenticate a request

Send your full API key in the `Authorization` header using the `Bearer` scheme. The [quickstart](/quickstart) shows a complete cURL request.

Every documented `/api/v1` endpoint requires an API key. A website sign-in session is not an API key. You do not need to send a cookie or a JSON request body for these GET requests.

If your key is missing, malformed, revoked, or otherwise invalid, you receive `401 Unauthorized` with `WWW-Authenticate: Bearer` and an `unauthorized` [problem response](errors).

## Rotate or revoke your key

Use the key's rotate action in **Chaves de API** to generate a replacement secret. Rotation invalidates the previous secret immediately. Save the replacement and update your server configuration.

Use the delete action to revoke a key you no longer need. Requests with that key then fail authentication.

Your keys share your account's rate limit and credits. Creating additional keys does not increase either allowance. See [Limits and credits](limits).

Keep your full key out of client-side code, public repositories, URLs, and logs. If you expose it, rotate or revoke it through your dashboard.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.