# Authentication

> Personal API keys, what each permission allows, and how to keep keys safe.

Every request carries a personal API key as a bearer token:

```sh
curl https://app.splot.health/v1/meals \
  -H "Authorization: Bearer $SPLOT_API_KEY"
```

A key acts as you: it reads and changes your own journal, and nothing else.

## Create a key

In the app, open **Account → API Keys**. Choose a name, a permission and how long the key lasts: 30, 90 or 365 days. The key is shown once, so copy it straight away. Keys start with `splot_pat_`.

You can have up to 20 active keys. To rotate one, create a replacement, switch to it, then revoke the old key. Revoking takes effect on the next request.

## Permissions

| Permission | Allows |
| --- | --- |
| Read | Listing and reading meals, searching foods, following your food corrections, and reading your settings, such as daily targets. |
| Read and write | Also creating, changing and deleting meals, saving and deleting your own foods, and changing your settings. |

A request the key's permission doesn't cover is answered with `403` and `insufficient_scope`. Keys can't manage other keys, connected assistants or your account.

## Keeping keys safe

- Send keys only in the `Authorization` header, never in a URL.
- Keep them in environment variables or a secret manager, not in code.
- Make sure logs and proxies leave the `Authorization` header out.
- Revoke a key in the app as soon as you no longer need it, or if it may have leaked.
