> ## Documentation Index
> Fetch the complete documentation index at: https://docs.refuseless.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> API keys, headers, and auth errors.

# Authentication

Every API call needs a bearer key.

```bash theme={null}
curl https://api.refuseless.dev/v1/models \
  -H "Authorization: Bearer $REFUSELESS_API_KEY"
```

* Header: `Authorization: Bearer <key>`
* No key → `401 invalid_key` / `Missing bearer API key.`
* Bad key → `401 invalid_key` / `Invalid API key.`

<Warning>
  Never ship keys in client-side code. Call Refuseless from your server and
  keep keys in environment variables or a secret store.
</Warning>

Out of credits mid-request? A non-streamed call returns `402
insufficient_credits`. A stream emits a
`{"error": {"code": "insufficient_credits"}}` event and stops. Top up and
retry — see [Errors](/guides/errors).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.