> ## Documentation Index
> Fetch the complete documentation index at: https://docs.levios.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate every levios REST API v1 request with an API key sent as a Bearer token, rotate keys safely, and scope access per Instagram account.

Every REST API v1 request requires a levios API key. Send the key as a Bearer
credential:

```http theme={null}
Authorization: Bearer <YOUR_LEVIOS_API_KEY>
```

API v1 does not accept OAuth access tokens or levios browser sessions. OAuth
is reserved for the [MCP server](/mcp/overview).

Keep API keys in server-side code or a secret manager. Do not expose them in a
browser, mobile application, public repository, log, or support message.

## Create an API key

Create and revoke keys in
[API key settings](https://levios.app/settings/api-keys). When you create a
key, choose its scopes and the Instagram accounts it can access. levios shows
the full secret once, so store it before you leave the page.

Send the key in the Bearer header:

```bash theme={null}
curl --request GET \
  --url "https://levios.app/api/v1/accounts" \
  --header "Accept: application/json" \
  --header "Authorization: Bearer ${LEVIOS_API_KEY}"
```

## Scopes and account access

A request must satisfy both the operation scope and the account access granted
to the key. API v1 currently uses these operation scopes:

* `automations:read` lists automations and reads one automation.
* `automations:write` creates, updates, and deletes automations.
* `automations:activate` activates or pauses an automation.
* `contacts:read_pii` reads complete contact records.
* `contacts:write` manages contact tags and assignments.
* `metrics:read` reads account and automation metrics.

The account catalog has no operation-specific scope, but it still requires a
valid API key. It returns only the accounts available to that key.

## Authentication failures

The API returns `401` with `api_unauthorized` when it cannot accept the API
key. A valid key without the required scope or account access returns `403`.

Do not use an error response to determine whether a key or account exists.
Revoke and replace a key through levios settings if you suspect exposure.

See [Errors](/guides/errors) for the response envelope and correlation IDs.
