> For the complete documentation index, see [llms.txt](https://docs.sectoral.xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sectoral.xyz/developer-api/auth-and-keys.md).

# Authentication and API Keys

One bearer token gives the REST API access to accounts, transfers and agent wallets. Each request has to include an API key issued by a Sectoral account.

***

## Creating a key

You generate keys in the **Developer** section of the dashboard:

1. Log in to Sectoral
2. Open **Dashboard → Developer → API Keys**
3. Click **Generate New Key**
4. Give it a label, such as `production`, `dev` or `internal-tool`
5. Store it securely right away, because you will only see it once

Each key is tied to the account that created it. A transfer sent through the API gets exactly the same confidentiality as one sent from the app. Privacy is not weakened just because a program is making the request.

***

## Authenticating requests

Include the key in the `Authorization` header of each request:

```
Authorization: Bearer <your_api_key>
```

Here is a complete request:

```bash
curl -X POST https://api.sectoral.xyz/v1/transfers \
  -H "Authorization: Bearer hc_live_xxxxxxxxxxxxxxxxxxxx" \
  -H "Content-Type: application/json" \
  -d '{
    "to": "@vendor",
    "amount": "125.00",
    "asset": "USDG",
    "confidential": true,
    "memo": "Invoice #4471"
  }'
```

***

## Live and test keys

| Prefix     | Network | Use                                                           |
| ---------- | ------- | ------------------------------------------------------------- |
| `hc_live_` | Mainnet | For production, where calls create real on-chain transactions |
| `hc_test_` | Testnet | For development, with no need for real USDG                   |

Build your integration with test keys. Requests made with them go to the Robinhood Chain testnet (chain ID 46630), so they never reach mainnet (chain ID 4663) or move real money.

***

## Key management

From the dashboard you can:

* **List** all of your keys along with when each was last used
* **Revoke** a key, which takes effect instantly
* **Inspect usage** for each key, including how many requests it made and how much USDG it moved

***

## Keeping keys secure

* Store keys in environment variables or a secrets manager, and never commit them to source control.
* Rotate a key as soon as you think it may have leaked.
* Give each environment its own key.
* Revoke keys you no longer use.

Anyone holding a live key can send funds out of your account, so protect it with the same care as a private key.

***

## What a key cannot do

An API key will never cause a transaction amount to be decrypted on the server for you. This limit is built into the system's design, not enforced by a rule someone could bend. If your integration needs to see a confidential amount, it has to decrypt it client-side using your account's decryption key, just like the Sectoral app.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.sectoral.xyz/developer-api/auth-and-keys.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
