# Authentication

A board or page key goes in either header:

```http
Authorization: Bearer <key>
X-API-Key: <key>
```

## Kinds of key

| Key | Where it's made | What it opens |
| --- | --- | --- |
| **Board key** `sbk_…` | A board's Settings → Developer | That board's `/v1/ingest/*` routes, within its scopes |
| **Page key** | A workspace page's (Leads, Deals…) Settings → Developer | That page's `/v1/ingest/*` routes, plus `external_id` retries |
A key only opens the routes its scopes cover; anything else answers `403`.

## The rest of the API

The other routes in the [API reference](/api-reference) are the ones the Specter app uses, and they
answer a **signed-in session**: `Authorization: Bearer <access token>` from `POST /v1/auth/signin`.
A board or page key is refused there.

## Scopes on a board key

| Scope | Allows |
| --- | --- |
| `read` | `GET /v1/ingest/board` — columns, rows and the write guide |
| `rows:write` | `POST /v1/ingest/rows` — add records. It never reads back what is already there |

Give each integration its own key with only the scopes it needs. A web form needs `rows:write` alone.

## A bad key

An unknown or revoked key answers `401`:

```json
{"error": {"message": "that key does not work here"}}
```

No key at all — or something that isn't an `sbk_…` key — answers `401` with
`a board API key is required`.
