> ## Documentation Index
> Fetch the complete documentation index at: https://rheon.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> One API key, sent as a Bearer token. What to send, and what a refusal looks like.

Every endpoint lives under `/v1` on `https://api.rheon.io` and takes your API key
as a Bearer token. There is one kind of key: it carries your products, corridors,
rate and ceiling, and works from your server, a page, or the playground on these
pages alike. Treat it as a secret: anyone holding it acts under its permissions
until it is rotated.

## Sending the key

<CodeGroup>
  ```bash cURL theme={null}
  curl -X POST "$RHEON_API/v1/deposit/quote" \
    -H "Authorization: Bearer $RHEON_API_KEY" \
    -H "Content-Type: application/json" \
    -d '{
      "source": { "address": "0x552008c0f6870c2f77e5cC1d2eb9bdff03e30Ea0", "chain": 8453, "token": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913" },
      "destination": { "address": "0x552008c0f6870c2f77e5cC1d2eb9bdff03e30Ea0", "chain": 42161, "token": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831" },
      "amount": "5000000",
      "method": "crypto"
    }'
  ```

  ```ts TypeScript theme={null}
  const res = await fetch(`${process.env.RHEON_API}/v1/deposit/quote`, {
    method: "POST",
    headers: {
      Authorization: `Bearer ${process.env.RHEON_API_KEY}`,
      "Content-Type": "application/json",
    },
    body: JSON.stringify(quoteRequest),
  });
  ```
</CodeGroup>

<Warning>
  **The playground on these pages calls the live API with the key you paste.** Crypto
  deposits run on production and move real money once the transaction is signed.
  There is no shared demo key: use your own, or copy the request into your backend.
</Warning>

## Getting a key

We issue it. **The key is shown once, at creation**: we keep only a fingerprint of
it, so a lost key cannot be recovered, only replaced. Tell us and we will issue a
new one; the old one stops working the moment the new one is in place.

## What the key may use

Read it from the API rather than asking us:
[`GET /v1/config`](/api-reference/configuration/what-this-key-may-use) answers
the `products` you may call, your `maxExecutionUsd`, and under `crypto` the chains
and tokens you may name. What each of those means for your integration, and why
a missing product is a refusal rather than a default, is on
[Rheon API](/integration/api#what-your-key-carries).

## What a refusal looks like

Every refusal uses the one error envelope, described on [Errors](/concepts/errors):

```json theme={null}
{ "environment": "production", "error": { "code": "chain_not_allowed", "message": "..." } }
```

| Status | Code | What happened |
| - | - | - |
| `401` | `unauthorized` | Missing, malformed, or unknown key. We do not say which. |
| `403` | `permission_denied` | Valid key, but it does not carry the product this endpoint needs. |
| `403` | `chain_not_allowed` | Valid key, but not enabled for that chain on that side. |
| `403` | `token_not_allowed` | Valid key, but not enabled for that token on that chain. |
| `403` | `execution_capped` | The transfer exceeds the key's execution ceiling. |
| `429` | `rate_limited` | Over your key's requests per second. Retry after a moment. |
