> ## Documentation Index
> Fetch the complete documentation index at: https://developers.flameproxies.com/llms.txt
> Use this file to discover all available pages before exploring further.

# API authentication

> How to authenticate with the FlameProxies Customer API using your API key: the two supported headers, where to find your key, and how to rotate or revoke it.

The Customer API authenticates every request with an **API key**. Keys start with `fp_live_`.

## Sending your key

Send your key with every request, using either of these headers:

<CodeGroup>
  ```bash Authorization header theme={null}
  curl https://flameproxies.com/api/customer/balance \
    -H "Authorization: Bearer fp_live_xxx"
  ```

  ```bash x-api-key header theme={null}
  curl https://flameproxies.com/api/customer/balance \
    -H "x-api-key: fp_live_xxx"
  ```
</CodeGroup>

Both headers work the same way. Use whichever your HTTP client makes easier.

A missing, invalid, or revoked key returns an `unauthorized` error:

```json theme={null}
{
  "error": "unauthorized",
  "message": "Human-readable error message."
}
```

<Note>
  **API key ≠ proxy credentials.** The API key authenticates calls to `flameproxies.com/api/customer`. Your package username and password authenticate proxy traffic through `proxy.flameproxies.com` — they're the credentials returned by [get a package](/api/packages/get) and used in the lines from [generate proxies](/api/proxies/generate). The two are managed separately and aren't interchangeable.
</Note>

## Getting your key

Your API key is on the [**API docs**](https://flameproxies.com/dashboard/api-docs) page of the dashboard, along with its status and your customer ID.

Keys are **shown only once**. Copy your key and store it securely when it's displayed — you can't view it again later.

## Rotating and revoking keys

You manage your key from the same dashboard page:

* **Rotate key** — replaces your key with a new one. Rotate any time, for example on a schedule or after someone leaves your team. Update your integrations with the new key.
* **Revoke key** — disables your key. Requests that use it fail with `unauthorized`.

When a key is active and ready for API requests, the dashboard shows its status as **Active**.

## Best practices

* Store your key in a secrets manager or environment variable, never in code or client-side bundles.
* Call the API only from your backend. Never expose the key in a browser or mobile app.
* Rotate the key immediately if you suspect it has leaked.

```python theme={null}
import os
import requests

API_KEY = os.environ["FLAME_API_KEY"]

resp = requests.get(
    "https://flameproxies.com/api/customer/balance",
    headers={"x-api-key": API_KEY},
)
print(resp.json())
```

## Next steps

<CardGroup cols={2}>
  <Card title="API quickstart" icon="rocket" href="/api/quickstart">
    Make your first API request.
  </Card>

  <Card title="Error handling" icon="triangle-exclamation" href="/api/errors">
    What to do when a request fails.
  </Card>
</CardGroup>
