> ## Documentation Index
> Fetch the complete documentation index at: https://docs.meetingkit.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate every request with your API key in the Authorization header.

The MeetingKit API authenticates with a personal API key sent in the `Authorization` header.
Get your key from your [API settings page](https://api.meetingkit.com/settings/personal/api).

Include the key in the `Authorization` header of every request:

<CodeGroup>
  ```bash cURL theme={null}
  curl "https://api.meetingkit.com/api/v1/meetings?workspace_id=wks_01k6a2r9s8x7c2dvq3m5n6p4ab" \
    -H "Authorization: $MEETINGKIT_API_KEY"
  ```

  ```javascript JavaScript theme={null}
  const response = await fetch(
    'https://api.meetingkit.com/api/v1/meetings?workspace_id=wks_01k6a2r9s8x7c2dvq3m5n6p4ab',
    {
      headers: { authorization: process.env.MEETINGKIT_API_KEY },
    },
  );
  ```

  ```python Python theme={null}
  import os
  import requests

  response = requests.get(
      "https://api.meetingkit.com/api/v1/meetings",
      params={"workspace_id": "wks_01k6a2r9s8x7c2dvq3m5n6p4ab"},
      headers={"Authorization": os.environ['MEETINGKIT_API_KEY']},
  )
  ```
</CodeGroup>

## Accepted header formats

The bare key is the canonical form. If your HTTP client or a generated SDK insists on an
auth scheme, these all authenticate too, and the scheme is case-insensitive:

```text theme={null}
Authorization: <your key>
Authorization: Bearer <your key>
Authorization: Token <your key>
```

## Keys and workspaces

Your API key is personal: requests act as your user, and you can access any
workspace you're a member of. Most endpoints take a `workspace_id` parameter
to select which one — list yours with `GET /workspaces`.

<Warning>
  Keep your API key secret. Don't commit it to version control or expose it in client-side code. If
  a key leaks, regenerate it from your API settings page.
</Warning>

## When authentication fails

Every failure returns `401 Unauthorized` with an [error](/api-reference/errors) whose
`code` tells you which kind it is:

| Situation | `code` | `message` |
| - | - | - |
| No `Authorization` header at all | `missing_api_key` | `Missing API key. Send it as "Authorization: <your key>".` |
| A header whose key matches no account | `invalid_api_key` | `Invalid API key.` |
| A valid key without access to the requested workspace | `unauthorized` | `Unauthorized` |

A request with no valid key has no pin: send the `Happyscribe-Version` header to get this
body.

A request that names no workspace when the endpoint needs one is a `400`, not a `401` —
see [Errors](/api-reference/errors).

## Versioning

Your key is pinned to the API version that was current the first time it was used, and
every response says which version served it. See [Versioning](/api-reference/changelog#versioning)
for the `Happyscribe-Version` header and how upgrades work.
