> ## Documentation Index
> Fetch the complete documentation index at: https://developers.reflection.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Create an API key and authenticate your requests

The Reflection API authenticates every request with an API key, sent in the `Authorization` header.

## Create an API key

<Note>
  The Reflection platform is in beta, and access is opening gradually. New sign-ups join a waitlist and can create API keys once their access is enabled.
</Note>

1. Sign in to the [Reflection platform](https://platform.reflection.ai).
2. Open **API Keys** and select the project the key is for.
3. Create the key and copy it. Its full value is shown only once, right after creation.

API keys belong to a project and to the user who created them:

* A key can make requests only against its project. Use separate projects to keep keys and usage apart, for example one per application or environment.
* A key is disabled if the user who created it is removed from the organization or the project.

If you can't create a key, ask an administrator of your organization for access. Some organizations must add a verified payment method before creating keys.

## Send the key

Pass the key in the `Authorization` header:

```http theme={null}
Authorization: Bearer <your API key>
```

The examples in these docs read the key from the `REFLECTION_API_KEY` environment variable:

<CodeGroup>
  ```bash cURL theme={null}
  curl https://api.reflection.ai/openai/v1/models \
    -H "Authorization: Bearer $REFLECTION_API_KEY"
  ```

  ```python Python theme={null}
  import os
  from openai import OpenAI

  client = OpenAI(
      base_url="https://api.reflection.ai/openai/v1",
      api_key=os.environ["REFLECTION_API_KEY"],
  )
  ```

  ```typescript TypeScript theme={null}
  import OpenAI from "openai";

  const client = new OpenAI({
    baseURL: "https://api.reflection.ai/openai/v1",
    apiKey: process.env.REFLECTION_API_KEY,
  });
  ```
</CodeGroup>

## Keep keys secure

* Treat a key like a password. Anyone who has it can make requests billed to your organization.
* Keep keys on your server. Don't embed them in browser or mobile apps, and don't commit them to source control.
* Load keys from environment variables or a secret manager.
* Revoke a key from the **API Keys** page if it may have been exposed, and replace it with a new one.

## Authentication errors

| Status | `error.code` | What to do |
| - | - | - |
| `401` | `missing_credentials` | Send an `Authorization` header. |
| `401` | `invalid_authorization_header` | Use the form `Authorization: Bearer <key>`. |
| `401` | `invalid_api_key` | Check that the key is complete and hasn't been revoked. |
| `403` | `organization_membership_required` | The key's user must be a member of the organization. |
| `403` | `account_restricted` | The user, organization, or key is restricted. Contact support. |
| `403` | `payment_method_required` | Verify a credit card in Billing before using API keys. |
| `403` | `plan_access_denied` | Your organization's plan doesn't include API key access. |

See [Errors](/errors) for the full list.
