# Authentication

> Authenticate every request with an X-API-Key header. Create, rotate and revoke keys from the dashboard.

Source: https://onlineresumeparser.com/api-docs/authentication · Markdown: https://onlineresumeparser.com/api-docs/authentication.md

Send your key in the `X-API-Key` header of every request. Only the [health check](https://onlineresumeparser.com/api-docs/health.md) is public.

```http
POST /api/v1/jobs/extract-criteria HTTP/1.1
Host: onlineresumeparser.com
X-API-Key: sk_xxxxxx_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Content-Type: application/json
```

- `Authorization: Bearer …` and keys in query strings are not accepted.
- Keys look like `sk_` + 6 hex characters + `_` + 32 hex characters. A malformed key is rejected as invalid.
- All keys of an account share its credit balance and work with every API.

## Manage keys

Create, name, rotate and revoke keys in [Dashboard → API keys](https://onlineresumeparser.com/dashboard/api-keys).

> **Warning: Rotation revokes the old key immediately.** There is no grace period. To rotate without downtime, create a second key, deploy it, then revoke the first one.

## Keep keys secret

- Call HireLayer from your backend. Never ship a key in browser, mobile or desktop code.
- Read it from an environment variable such as `HIRELAYER_API_KEY` and keep it out of version control.
- Use one key per environment or service, so you can revoke one without touching the others.

```env
# .env — server-side only, never commit it
HIRELAYER_API_KEY=sk_xxxxxx_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
```

## Authentication errors

| Status | Body | Cause |
| --- | --- | --- |
| `401` | `{"error": "Missing API Key"}` | No `X-API-Key` header. |
| `401` | `{"error": "Invalid API Key"}` | Malformed, unknown or revoked key. |
| `403` | `{"error": "Insufficient credits available"}` | Valid key, but no credit left. See [Limits and credits](https://onlineresumeparser.com/api-docs/limits.md). |

## Next

- [Errors and retries](https://onlineresumeparser.com/api-docs/errors.md): Error format, every status code and message, and when to retry a HireLayer API call.
- [Limits and credits](https://onlineresumeparser.com/api-docs/limits.md): How credits are consumed, request size and batch limits, timeouts and concurrency guidance for the HireLayer APIs.
