> ## Documentation Index
> Fetch the complete documentation index at: https://docs.storerocket.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Create a token, choose permissions, and authenticate requests.

## Create a token

Open [API Tokens](https://storerocket.io/app/api-tokens), create a token, and copy it securely. The full token is shown only when it is created.

The token belongs to your user account and can access projects that account belongs to. Location endpoints also check the project's API access and the token's permissions.

## Send the token

```bash theme={null}
curl 'https://storerocket.io/api/v2/projects' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Accept: application/json'
```

Use `Authorization: Bearer`, not an `X-API-Key` header or a token in the URL. Keep tokens in server-side integrations and out of public website code.
For JSON request bodies, also send `Content-Type: application/json`.

## Location permissions

| Permission | Methods |
| - | - |
| `location:read` | GET location list and GET one location |
| `location:create` | POST location |
| `location:update` | PATCH and PUT location |
| `location:delete` | DELETE location |

Select the permissions your integration needs when creating its token. Revoke an unused or compromised token from the same API Tokens page.

## Authentication errors

A missing, expired, revoked, or invalid token returns `401`:

```json theme={null}
{"message":"Unauthenticated."}
```

A valid token without the required permission, or a project without API access, returns `403`. A project or location outside your access returns `404`. See [errors](/api/errors).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.