---
title: Authentication
description: Authenticate API requests safely with a Bearer key.
---

Send your API key in the `Authorization` header on every authenticated request.

```http
Authorization: Bearer <API_KEY>
```

Store the key in a server-side environment variable or secret manager. Do not place it in browser code, mobile binaries, or a public repository. For browser products, call Sawtak Arabi through your own server so the key stays private.

## Scopes

Keys can be limited to functional scopes. Use the smallest scope set required by the integration:

| Scope | Allows |
| --- | --- |
| `tts` | Text-to-speech synthesis |
| `voices` | Voice catalog and voice management |
| `usage` | Account introspection and usage reporting |

An unrestricted key can access the standard API operations. A scoped key that lacks a required permission receives `403` with the `insufficient_scope` error code.

## Verify a key

Call `GET /v1/me` with a key that has the `usage` scope. A successful response confirms the credential and returns account information. If authentication fails, replace the key instead of repeatedly retrying: repeated failed attempts can be throttled.

```bash
curl --fail --show-error https://api.sawtakarabi.ai/v1/me \
  -H "Authorization: Bearer $SAWTAK_API_KEY"
```

See [Errors](/docs/errors) for the response envelope and [Request limits](/docs/limits) for throttle handling.
