# Authentication

Every data endpoint needs an API key. Discovery endpoints are public and need none: `/v1/catalog`, `/v1/search`, `/v1/status`, `/v1/calendar`, `/v1/plans`, `/v1/commodities/items` and `/v1/commodities/cities`.

## Sending your key

The preferred way is the `X-API-Key` header:

```bash
curl -H "X-API-Key: pk_live_xxx" \
  "https://api.pakdatahub.com/v1/series/rates.kibor.3m"
```

For quick tests, pandas `read_csv` or a spreadsheet import, you can pass it as a query parameter instead:

```
https://api.pakdatahub.com/v1/series/rates.kibor.3m?api_key=pk_live_xxx
```

Avoid the query-parameter form in production, because URLs end up in logs and browser history.

## Key format and storage

- Keys start with `pk_live_`.
- A key is shown **once**, when it is created. We store only a hash, so a lost key can't be recovered; revoke it and create a new one.
- Each account can hold up to **3 active keys**, for example one per environment. See [`/v1/keys`](https://pakdatahub.com/docs/api-account-keys.md).
- Each key's `last_used_at` is recorded, updated at most once a minute, so you can spot unused keys.

## Session tokens (dashboard)

The web dashboard signs you in with email and password or Google, and holds a **session token**. The account-management endpoints accept either credential:

| Endpoint | API key | Session token (`X-Session-Token`) |
|---|---|---|
| `/v1/series`, `/v1/funds`, all data endpoints | yes | no |
| `/v1/account`, `/v1/keys`, `/v1/usage`, `/v1/webhooks`, `/v1/billing/portal` | yes | yes |

See [Auth endpoints](https://pakdatahub.com/docs/api-auth.md) for signup, login and logout.

## What happens when a key is wrong

```json
{ "success": false, "error": { "code": "unauthorized", "message": "missing API key" } }
```

A missing or invalid key returns `401 unauthorized`. The other auth-related errors are:
- `402`: this month's free calls are used up, or the subscription is inactive.
- `403`: the feature needs a higher plan (e.g. revision vintages need Pro).

See [Errors & rate limits](https://pakdatahub.com/docs/errors-rate-limits.md).

## Rotating a key

1. Create a new key (`POST /v1/keys` or the dashboard).
2. Deploy it.
3. Revoke the old one (`DELETE /v1/keys/{id}`).

Revocation takes effect immediately.

---
Source: https://pakdatahub.com/docs/authentication - PakDataHub docs index: https://pakdatahub.com/docs/llms.txt
