# Authentication

Every IntelCenter API request requires a valid API key sent as a Bearer token.

## Header

```text
Authorization: Bearer YOUR_API_KEY
```

## REST Example

```bash
curl --request GET \
  --url "https://api.intelcenter.com/v1/icd/videos?page=1&per_page=10" \
  --header "Authorization: Bearer YOUR_API_KEY"
```

## MCP

Use the same Bearer-token method for:

- `POST /mcp-icd`
- `POST /mcp-all`

A compatible client should store the token in its secure authentication configuration. MCP tool discovery and calls remain limited by the API key's permissions.

## Key Security

- Keep API keys in a server-side secret store.
- Never place keys in browser code, mobile application bundles, public repositories, prompts, screenshots, or logs.
- Use separate keys for production and non-production work.
- Rotate a key immediately if it may have been exposed.
- Do not share one key across unrelated applications or teams.
- Apply least privilege when selecting datasets and capabilities.

## Common Errors

### Missing or Invalid Key

```http
HTTP/1.1 401 Unauthorized
```

Confirm that the header uses `Bearer`, contains one space before the key, and is being sent to the intended environment.

### Insufficient Permission

```http
HTTP/1.1 403 Forbidden
```

The key is valid but does not have the requested dataset or capability.

See [Access and Permissions](/access-and-permissions) for authorization behavior.
