> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stablemesh.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate every request with a secret API key in the X-API-KEY header.

Send your secret API key in the `X-API-KEY` header on every request.

```bash theme={null}
curl -X POST https://api.stablemesh.io/v1/account/balance \
  -H "X-API-KEY: smk_live_..." \
  -H "Content-Type: application/json" \
  -d '{}'
```

***

## Create a key

1. In the dashboard, go to **Settings → API keys**.
2. Create a key. You confirm with your passcode and an emailed code.
3. Copy the key. It is shown **once**. StableMesh stores only a hash of it.

Production keys start with `smk_live_`.

When you create a key you can:

* **Restrict it to IP addresses.** Use exact IPv4 or IPv6 addresses, or a `a.b.c.*` range, up to 20 entries. Requests from anywhere else are refused with `11003`.
* **Set an expiry date.** After it, the key stops working.

You can have up to **5 active keys**. Revoke a key in the same place, and it stops working at once.

<Warning>
  **An API key has full control of your cards and balance.** Use it only from your server. Never put it in a web page, a mobile app, or source control. The API doesn't answer browser cross-origin requests.
</Warning>

***

## Rate limit

Each key can make **20 requests per second**. Above that, requests are refused with HTTP `429` and code `11004`. Wait a moment, then retry.

***

## Authentication errors

| HTTP | Code | Meaning |
| - | - | - |
| 401 | `11002` | The key is missing, unknown, revoked or expired, or your account is not active |
| 403 | `11003` | The request came from an IP address that isn't on the key's allowlist |
| 429 | `11004` | The key is over its rate limit |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.