> For the complete documentation index, see [llms.txt](https://padiwise.gitbook.io/padiwise/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://padiwise.gitbook.io/padiwise/getting-started/authentication.md).

# Authentication

{% hint style="danger" %}
**Secure your secret key**

Do not commit your secret token to git, or use them in client-side code.
{% endhint %}

This **secret API key** grants unrestricted access to **Padiwise's** API and authorizes all API calls. If there's any suspicion of a security breach, the secret key can be reset directly from your **Padiwise** dashboard. To access **Padiwise** endpoints, you must first obtain an **access token** by sending a request to the login endpoint using the OAuth 2.0 protocol.

<figure><img src="/files/K92CsIVm6VoZ61XSqL8t" alt=""><figcaption></figcaption></figure>

The `Authorization` header should be formatted as:

```
--header 'Accept: application/json' \
--header 'Authorization: Bearer {{ access_token }}'
```
