> ## Documentation Index
> Fetch the complete documentation index at: https://docs.amps.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Create an API key, send it with every request, and choose between sandbox and live.

Every request needs an API key. The key also decides whether you reach sandbox or live.

## Get a key

Create keys in the [dashboard](https://app.amps.ai) under **API Keys**. A key belongs to the environment the dashboard is switched to when you create it. The full key is shown once, so copy it then.

<Info>
  New to Amps? [Request sandbox access](https://tally.so/r/D4zgZE).
</Info>

## Send the key

Put the key in the `x-api-key` header.

```bash theme={null}
curl https://api.amps.ai/battery \
  -H "x-api-key: $AMPS_API_KEY"
```

A missing key returns `401 UNAUTHORIZED`. An unrecognised or revoked key returns `401 INVALID_API_KEY`.

## Sandbox and live

The prefix tells you which environment a key belongs to. Both use the same host.

| Prefix | Environment | Devices |
| - | - | - |
| `sk_test_` | Sandbox | Simulated. Safe to experiment with. |
| `sk_live_` | Live | Your end users' real devices. |

Data never crosses environments: a sandbox key can't see live devices, and a live key can't see sandbox devices. Live keys only work once your account is enabled for live. Until then they return `403 LIVE_ACCESS_DISABLED`.

To move to production, swap your `sk_test_` key for an `sk_live_` key and drop `sandbox=true` from your [Link UI](/guides/link-ui) URLs. Nothing else changes.

## Check the environment

Every authenticated response reports the environment that served it in `meta.environment`.

```json theme={null}
{
  "success": true,
  "data": { "...": "..." },
  "meta": { "requestId": "req_8a2Bf3kP", "environment": "sandbox" }
}
```

## Rate limits

If you send too many requests, you get `429 RATE_LIMIT_EXCEEDED`. Responses don't include rate-limit headers, so retry with exponential backoff.

## Keep keys safe

* Call the API from your server. Never ship a key in a browser or mobile app.
* Load keys from environment variables or a secrets manager. Don't commit them.
* Use a separate key per service, so you can revoke one without breaking the others.
* To rotate, create a new key, deploy it, then delete the old one in the dashboard. A deleted key stops working.

## Next steps

<CardGroup cols={2}>
  <Card title="Link UI" icon="link" href="/guides/link-ui">
    Let end users connect their devices.
  </Card>

  <Card title="Error codes" icon="list" href="/guides/error-handling/error-codes">
    Every authentication and access error.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.