> This page is for version v1 (default).
> For other versions, use one of these documentation indexes:
> - v1 (default): https://docs.plextera.com/v-1/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.plextera.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.plextera.com/_mcp/server.

# Authentication

Authenticate requests to the Plextera Public API with an API key issued for your client integration.

## Get an API key

API keys are managed in Plextera account settings.

```
Plextera -> Account settings -> API -> API keys
```

### Open account settings

Sign in to Plextera, open your user or workspace menu, and select **Account settings**.

### Open the API tab

In Account settings, open the **API** tab. This is where API access for your workspace is managed.

### Copy the key

Copy the API key for the integration you are building. Store it in a secrets manager or environment variable before using it in requests.

> **Info**
>
> If you do not see the API tab or cannot copy a key, ask a workspace administrator or your Plextera account team to enable API access.

## API key header

Pass your API key in the `Authorization` header using the `api-key` prefix:

```bash
Authorization: api-key YOUR_API_KEY
```

For example:

```bash
curl https://api.plextera.com/api/public/v1/files \
  -H "Authorization: api-key YOUR_API_KEY"
```

> **Warning**
>
> The header value must include the `api-key` prefix followed by a space and the key. Sending the key alone without the prefix will result in a 401.

## Request context

Each API key gives access to one Plextera workspace. You do not pass a workspace identifier in requests.

## Usage guidelines

* Use one API key per integration (e.g., one key per environment: staging, production).
* The same key is valid across all API surfaces: Files, Document Insights, Workflows, and Event Subscriptions.
* Store keys in environment variables or a secrets manager. Do not commit them to source control.

## Key rotation

To rotate a key, issue a new one and update your integration before deactivating the old key. There is no grace period once a key is deactivated.

## Next steps

* [API Reference](/api/api-reference) - full authenticated endpoint reference
* [Event Subscriptions](/guides/core-guides/event-subscriptions) - configure webhook push notifications