> ## Documentation Index
> Fetch the complete documentation index at: https://docs.reap.video/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Learn how to authenticate your API requests

> **For AI agents:** a documentation index is at [/llms.txt](/llms.txt). Every page is also available as markdown, just append `.md` to the URL.

## API Key Authentication

The Reap Automation API uses API key authentication. You'll need to include your API key in the `Authorization` header of every request.

### Getting Your API Key

<video controls playsInline width="100%" poster="/images/help-center/api-keys-poster.jpg" src="https://mintcdn.com/reap/KDevp7fQ_nNnw83g/images/help-center/api-keys.mp4?fit=max&auto=format&n=KDevp7fQ_nNnw83g&q=85&s=a3b4ab9331ff627ee71f6cd6dec871e3" title="Create an API key in Reap" data-path="images/help-center/api-keys.mp4" />

1. Log in to your Reap dashboard
2. Click **API Keys** in the left sidebar. You can also open your avatar menu in the top right and go to **Settings** > **API Keys**.
3. Click **Create a Secret Key**
4. Give your key a descriptive name. This is only for your reference.
5. Optionally, set an expiration date for the key. Keys are not expired by default.
6. Click **Create Key** to generate the API key.
7. Copy the generated API key (store it securely - you won't be able to see it again)

<Warning>
  Keep your API key secure! Don't commit it to version control or share it publicly. Store it in environment variables or a secure configuration management system.
</Warning>

### Making Authenticated Requests

Include your API key in the `Authorization` header with the `Bearer` prefix:

```bash theme={"system"}
curl -X GET "https://public.reap.video/api/v1/automation/get-all-projects" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json"
```

### Authentication Headers

| Header | Value | Required |
| - | - | - |
| `Authorization` | `Bearer YOUR_API_KEY` | Yes |
| `Content-Type` | `application/json` | Yes |

## API Key Management

### Security Best Practices

<CardGroup cols={2}>
  <Card title="Environment Variables" icon="shield">
    Store your API key in environment variables rather than hardcoding it in your application.
  </Card>

  <Card title="Regular Rotation" icon="refresh">
    Rotate your API keys regularly for enhanced security.
  </Card>

  <Card title="Least Privilege" icon="lock">
    Use separate API keys for different environments (development, staging, production).
  </Card>

  <Card title="Monitor Usage" icon="chart-line">
    Monitor your API key usage to detect any unauthorized access.
  </Card>
</CardGroup>

### Key Expiration

API keys do not expire by default. You can:

* Set custom expiration dates when creating keys
* Create non-expiring keys (recommended for production)
* Monitor expiration dates in your dashboard
* Revoke keys at any time

### Revoking API Keys

To revoke an API key:

1. Click **API Keys** in the left sidebar of your dashboard
2. Find the key you want to revoke
3. Click the trash icon next to the key

<Warning>
  Revoking an API key immediately invalidates all requests using that key. Make sure to update your applications before revoking keys.
</Warning>

## Rate Limiting

Rate limits apply **per endpoint, per API key**. Each endpoint keeps its own budget,
so draining `get-project-status` leaves `create-clips` untouched.

| Endpoint kind | Requests / minute |
| - | - |
| Reads (`get-*`) | 60 |
| Writes (updates, deletes, publishing, billing links, `get-upload-url`) | 30 |
| Project creation (`create-clips`, `create-captions`, `create-transcription`, `create-reframe`, `create-dubbing`) | 10 |

Exceeding a budget returns `429 Too Many Requests`:

```json theme={"system"}
{
  "error": "Rate limit exceeded: 60 per 1 minute"
}
```

### Rate Limit Headers

| Header | Description |
| - | - |
| `X-RateLimit-Limit` | Requests allowed per minute on the endpoint you called |
| `X-RateLimit-Remaining` | Requests left in the current window for that endpoint |
| `X-RateLimit-Reset` | Unix timestamp (whole seconds) when the window resets, e.g. `1789847051` |
| `Retry-After` | Seconds to wait before retrying. Sent on `429` responses |

<Note>
  Treat `X-RateLimit-Remaining` as advisory. Counters are tracked per API server process,
  so consecutive requests can report slightly different values and the number can go up as
  well as down. On a `429`, `Retry-After` is the value to back off on.
</Note>

## Error Responses

### Authentication Errors

| Status Code | Error | Description |
| - | - | - |
| `401` | Unauthorized | Missing or invalid API key |
| `403` | Forbidden | API key doesn't have required permissions |
| `429` | Too Many Requests | Rate limit exceeded |

### Example Error Response

```json theme={"system"}
{
  "error": "Unauthorized",
  "message": "Invalid API key",
  "status": 401
}
```

## Testing Authentication

Test your API key with a simple request to get your presets:

```bash theme={"system"}
curl -X GET "https://public.reap.video/api/v1/automation/get-all-presets" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json"
```

A successful response indicates your authentication is working correctly.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.