> ## Documentation Index
> Fetch the complete documentation index at: https://www.mapsdata.io/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate Mapsdata API requests and manage keys safely.

All public API endpoints require a Mapsdata API key in the `x-api-key` request header.

```bash theme={null}
curl "https://www.mapsdata.io/api/v1/account" \
  -H "x-api-key: md_live_your_key"
```

## Create and manage keys

Open [API access](https://www.mapsdata.io/api-access) while signed in. You can create, reveal, copy, rename, and revoke keys there. Use a separate named key for every integration so usage can be attributed and one integration can be rotated without interrupting another.

<div className="callout mint-my-5 mint-rounded-xl mint-border mint-border-[#656c2e]/30 mint-bg-[#656c2e]/10 mint-px-5 mint-py-4 mint-text-sm mint-text-[#4d5321]">
  Never place an API key in browser code, a Git repository, screenshots, analytics events, or logs. Load it at runtime from your server's secret manager or environment.
</div>

Keys belong to the signed-in account. They can read only that account's searches and enrichment jobs, and share the account's subscription, credits, concurrency allowance, and 1,000-request rolling rate limit.

## Authentication errors

| Status | Meaning |
| - | - |
| `401` | The header is missing, the key is invalid or revoked, or its owner no longer exists. |
| `404` | The authenticated account does not own the requested job, or the wrong endpoint family was used. |
| `429` | The account exceeded its shared request or active-job limit. |
| `503` | The production rate-limit service is unavailable. Retry later. |

Revocation takes effect on the next request. Treat an exposed key as compromised: revoke it, issue a replacement, update the integration, and verify recent activity in **API analytics**.
