# Authentication

> Authenticate every request with a workspace API key.

Canonical URL: https://gensiv.com/docs/authentication
Product: Gensiv — Become the brand AI recommends

---

The Gensiv API uses API keys. Each key belongs to one workspace and can read every brand in that workspace.

## Plan and permissions [#plan-and-permissions]

* API access is included in every paid plan: every **Pro** tier and **Enterprise**.
* Workspace **owners** and **admins** can create and delete keys. Members cannot.
* A workspace can have up to **10** keys.
* If the workspace no longer has an active plan, its keys stop working until a plan is active again. The keys are not deleted.

## Send the key [#send-the-key]

Send the key as a bearer token in the `Authorization` header:

```bash
curl https://api.gensiv.com/v1/brands \
  -H "Authorization: Bearer $GENSIV_API_KEY"
```

If your tool cannot set an `Authorization` header, send the key in an `X-Api-Key` header instead:

```bash
curl https://api.gensiv.com/v1/brands \
  -H "X-Api-Key: $GENSIV_API_KEY"
```

Keys start with `gsk_`. The first characters of each key are shown next to its name in **Settings → API keys**, so you can tell your keys apart.

## Keep keys safe [#keep-keys-safe]

<Callout type="warn">
  Treat an API key like a password. Anyone with the key can read your workspace's data.
</Callout>

* Store keys in environment variables or a secrets manager, never in source code.
* Do not use a key in code that runs in a browser or mobile app, where users can read it.
* Create a separate key for each integration, so you can delete one without affecting the others.
* If a key is exposed, delete it in **Settings → API keys** right away. Deleted keys stop working immediately.

## Errors [#errors]

| Status | Code            | Meaning                                           |
| ------ | --------------- | ------------------------------------------------- |
| `401`  | `unauthorized`  | The key is missing, invalid, disabled or expired. |
| `403`  | `plan_required` | The workspace does not have an active plan.       |

See [Errors](/docs/errors) for the full list.