> ## Documentation Index
> Fetch the complete documentation index at: https://developer.peoplewisher.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate Peoplewisher API requests with an API key.

Peoplewisher uses API keys for server-to-server authentication.

## Get your API key

Sign in to Peoplewisher and open:

**Settings → API**

Copy the API key associated with the account you want to integrate.

Treat the key like a password. Store it in a server-side secret manager or environment variable.

## Send the key

Include the key in the `Authorization` header:

```http theme={null}
Authorization: Bearer YOUR_PEOPLEWISHER_API_KEY
```

Example:

```bash theme={null}
curl https://api.peoplewisher.com/v1/contacts \
  -H "Authorization: Bearer $PEOPLEWISHER_API_KEY"
```

## Do not expose API keys

Never put a Peoplewisher API key in:

* browser-side JavaScript
* public mobile application code
* frontend environment variables
* public Git repositories
* client-visible URLs

The API is intended for server-to-server requests.

## Authentication errors

If the key is missing or invalid, the API returns `401 Unauthorized`.

```json theme={null}
{
  "success": false,
  "error": "unauthorized",
  "message": "Invalid or missing API key."
}
```

A key only grants access to the Peoplewisher account it belongs to. Your application does not need a separate Peoplewisher key for every contact; use the appropriate account key and keep your own tenant mapping where applicable.
