> ## Documentation Index
> Fetch the complete documentation index at: https://docs.jitra.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate Jitra Public API requests with an Organization API key using x-api-key or Bearer authentication.

Every Jitra Public API endpoint requires an API key issued for your Organization.

## Send the API key

Use either authentication method. Both carry the same Organization API key.

<Tabs>
  <Tab title="x-api-key">
    ```bash theme={null}
    curl --request GET \
      --url https://api.jitra.app/public/v1/objects \
      --header 'x-api-key: <api_key>'
    ```
  </Tab>

  <Tab title="Bearer">
    ```bash theme={null}
    curl --request GET \
      --url https://api.jitra.app/public/v1/objects \
      --header 'Authorization: Bearer <api_key>'
    ```
  </Tab>
</Tabs>

<Note>
  Send one authentication header per request. You do not need to send both.
</Note>

## Authentication errors

A missing, invalid, or expired API key returns `401 Unauthorized`.

```json theme={null}
{
  "statusCode": 401,
  "errorCode": "ERR999",
  "message": "Unauthorized",
  "timestamp": "2026-05-17T01:00:00.000Z"
}
```

## Secure key handling

* Store API keys in a server-side secrets manager or protected environment variable.
* Never commit keys to a repository.
* Never expose keys in browser or mobile client code.
* Never include keys in URLs, screenshots, or application logs.
* Rotate the key from Jitra if it is exposed or compromised.
* Use separate keys for separate integrations when your Organization's setup allows it.

<Warning>
  An API key grants access to data available to its Organization. Treat it as a production secret.
</Warning>
