# Authentication · PostLake Docs > Markdown version of https://postlake.dev/docs/authentication — canonical page for humans. > PostLake is the social media API for AI agents: https://postlake.dev/llms.txt Every request to the API carries a secret **API key** that proves it's really you. A key is a long password for a program — anything holding it can post as you — so keep it secret. Keys look like `sk_live_…`. ## Get a key - In your [dashboard](https://app.postlake.dev), open your account menu (top right) and click **API Keys**. - Optionally name it after the app or environment it's for (e.g. `CI server`, `Zapier`) so you can revoke that one later without touching the rest. Click **Create API key**. - Copy the key **now** — it's shown only once. PostLake stores just a scrambled version, so it can never show it to you again. Lost it? Make a new one and delete the old. ## Use it on a request Send the key in a request header called `Authorization`, in the form `Bearer YOUR_KEY`. A "header" is just an extra line of info attached to the request; `Bearer` is the standard word that means "the bearer of this token is allowed in". With curl, the `-H` flag adds that header: ``` curl https://api.postlake.dev/v1/me \ -H "Authorization: Bearer sk_live_YOUR_KEY" ``` Every endpoint expects this same header. Leave it off (or mistype the key) and you get a `401 Unauthorized` back. The `/v1/me` call above is the quickest way to check a key is valid — it just echoes your account. ## Revoking a key On the same **API Keys** page, click **Revoke** next to any key. It stops working immediately — do this the moment a key might have leaked (committed to a public repo, pasted in a chat). Because you can name and revoke keys one at a time, a leak of one key never forces you to rotate the others. ## Keys are server-side only PostLake keys are **secret** server-side keys (prefix `sk_live_`). There's no separate "publishable" key — every endpoint is server-to-server, so never embed a key in a browser, mobile app, or public repo. **Agents connect differently.** If you're connecting an AI agent over MCP, it authenticates via OAuth — no API key is pasted into the chat. See [MCP server](https://postlake.dev/docs/mcp).