> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# API authentication

> Authenticate server-side requests with an Aptranet access key and secret.

API authentication requires two values from a project-scoped API key.

<ParamField header="Authorization" type="string" required>
  `Bearer ` followed by the access key. Access keys begin with `APTRANET_`.
</ParamField>

<ParamField header="Aptranet-Secret" type="string" required>
  The current secret for the access key.
</ParamField>

```bash theme={null}
curl https://api.aptranet.com/cloud-cdn/distributions \
  --header "Authorization: Bearer APTRANET_REPLACE_WITH_ACCESS_KEY" \
  --header "Aptranet-Secret: REPLACE_WITH_SECRET"
```

## How authentication works

The Gateway hashes the supplied secret, compares it with the key record, confirms that the key is active, and loads its project and permission document. Product routes then authorize the requested action.

## Store credentials

* Use a managed secret store or protected deployment secret.
* Keep access keys and secrets out of source control, frontend bundles, screenshots, and logs.
* Use separate keys for each workload and environment.
* Scope each key to the minimum operations it performs.

## Rotate a secret

Rolling a secret replaces the current secret immediately. For deployments that need overlap, create a second key with the same minimum permissions, deploy it, verify it, and then disable and delete the old key.

<Warning>
  Never send API credentials to a hostname other than `api.aptranet.com`. Aptranet support will not ask you for a secret.
</Warning>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.