> ## Documentation Index
> Fetch the complete documentation index at: https://docs.dmand.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Authenticate Dmand AI API Requests with Your API Key

> Dmand AI uses Bearer authentication with an optional API key header. Learn where to find your API key, how to send it, and how to keep it secure.

The Dmand AI API uses Bearer authentication. Every request to a public endpoint must include a valid API key in the `Authorization` header. Requests without a key, or with an invalid or inactive key, are rejected.

## Get your API key

API keys are issued by the Dmand AI team. If you need a new key or want to rotate an existing one, contact [`hello@dmand.ai`](mailto:hello@dmand.ai).

## Send the key in every request

Include your key in the `Authorization` header as a Bearer token:

```text theme={null}
Authorization: Bearer YOUR_API_KEY
```

You can also send the key in the `X-API-Key` header as an alternative.

## Example request

The example below submits an NPI for email enrichment. Replace `YOUR_API_KEY` with your actual key.

<CodeGroup>
  ```bash cURL theme={null}
  curl -X POST https://ext-api.dmand.ai/api/v1/email \
    -H "Authorization: Bearer YOUR_API_KEY" \
    -H "Content-Type: application/json" \
    -d '{"npi": "1003158791", "enrichment_email_type": "any"}'
  ```

  ```python Python theme={null}
  import requests

  url = "https://ext-api.dmand.ai/api/v1/email"
  headers = {
      "Authorization": "Bearer YOUR_API_KEY",
      "Content-Type": "application/json",
  }
  payload = {"npi": "1003158791", "enrichment_email_type": "any"}

  response = requests.post(url, headers=headers, json=payload)
  print(response.json())
  ```

  ```javascript JavaScript theme={null}
  const response = await fetch("https://ext-api.dmand.ai/api/v1/email", {
    method: "POST",
    headers: {
      Authorization: "Bearer YOUR_API_KEY",
      "Content-Type": "application/json",
    },
    body: JSON.stringify({
      npi: "1003158791",
      enrichment_email_type: "any",
    }),
  });

  const data = await response.json();
  console.log(data);
  ```
</CodeGroup>

## Error responses

Missing or invalid API keys are rejected. Revoked or inactive keys return `403 Forbidden`. Contact the Dmand AI team to rotate or reactivate the key.

Validation errors return `422 Unprocessable Entity` with a body like:

```json theme={null}
{
  "detail": [
    {
      "loc": ["body", "npi"],
      "msg": "Field required",
      "type": "missing"
    }
  ]
}
```

## Keep your key secure

Never expose your API key in client-side code, public repositories, or browser-based applications. Store it in a secret manager or environment variable on your server. If you suspect a key is compromised, contact the Dmand AI team to revoke it immediately.
