> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tryprofound.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Create a Profound API key and use it to authenticate your REST API requests

<Info>
  **Available on**: the Enterprise plan

  **Find it in**: Settings in the organization name menu at the top left of the screen > Account > API Keys
</Info>

## Overview

To authenticate your API requests, you need an API key. This key identifies and authorizes your requests, ensuring only authorized users can access resources.

Your API key provides access to all data available to your organization, including categories, regions, and category reports.

## Getting Your API Key

<Steps>
  <Step title="Navigate to the API key generation portal">
    1. Sign into the platform. Select your organization name at the top left of the screen, then select **Settings**.
    2. In the left sidebar under **Account**, select **API Keys**. This will show your key generation portal and a table of your keys.
  </Step>

  <Step title="Configure and create your key">
    1. In the **Create API Key** banner, enter a **key name** and select the **Expiration** period.
    2. Select **Create API Key** to generate the key.

    <Note>
      For added security, you will not be able to retrieve your key again. Copy and store your API key securely before proceeding.
    </Note>

    Your API keys are displayed in a table on the **API Keys** page. Return to this page at any time to see your keys, check expiry dates, or revoke an existing key.
  </Step>
</Steps>

## Authentication Methods

You can authenticate your requests using either method below:

### Header Authentication (Recommended)

Include your API key in the `X-API-Key` header:

<CodeGroup>
  ```http Header Method theme={null}
  POST /v1/reports/visibility HTTP/1.1
  Host: api.tryprofound.com
  X-API-Key: your_api_key_here
  Content-Type: application/json
  ```

  ```bash cURL theme={null}
  curl -X POST "https://api.tryprofound.com/v1/reports/visibility" \
    -H "X-API-Key: your_api_key_here" \
    -H "Content-Type: application/json"
  ```
</CodeGroup>

## API Key Scope & Permissions

Your API key provides access to:

* **Organization Data**: All data belonging to your organization
* **Categories**: Available data categories and their metadata
* **Regional Data**: Location-based information and filters
* **Reports**: Generated reports and analytics for your categories
* **Raw Data**: Unprocessed data within your accessible categories

## Security Best Practices

* **Keep keys private**: Your API key is sensitive information. Never share it publicly or commit it to version control. Store it securely and treat it like a password.
* **Use environment variables**: Store keys in environment variables or secure configuration files.
* **Rotate regularly**: Consider rotating your API keys periodically for enhanced security.
* **Monitor usage**: Check your API usage regularly to detect any unauthorized access.

## Authentication Errors

Common authentication errors and their meanings:

| Status Code | Error | Description |
| - | - | - |
| `401 Unauthorized` | Invalid API key | The provided API key is incorrect or expired |
| `403 Forbidden` | Insufficient permissions | Your API key doesn't have access to the requested resource |
| `429 Too Many Requests` | Rate limit exceeded | You've exceeded your API key rate limit |

## Need Help?

If you encounter authentication issues, [contact support](mailto:support@tryprofound.com) for assistance.
