# Your API key

Every request carries your API key. The same key works for the API and for the MCP server.

## Send your key

Put it in the `Authorization` header, after the word `Bearer`.

**The header**

```http
Authorization: Bearer $LOCALSCREENSHOT_API_KEY
```

- The key is only read from that header. A key written in the address is not accepted: an address ends up in logs, in browser history and in `Referer` headers.
- A missing or wrong key gets the error `unauthorized`, with status 401.
- Too many wrong keys from the same IP address are slowed down with `rate_limited`.

**Check that your key works**

```bash
curl "https://api.localscreenshot.com/v1/credits" \
  -H "Authorization: Bearer $LOCALSCREENSHOT_API_KEY"
```

**200**

```json
{
  "credits": { "remaining": 50 },
  "costs": { "base": 1, "surcharges": { "country": 1 } },
  "limits": { "requests_per_minute": 10, "concurrent_screenshots": 2 }
}
```

## Create and copy a key

Keys are made in the [dashboard](https://localscreenshot.com/dashboard), under **Connect**.

- A key starts with `lss_live_`, followed by 40 letters and digits.
- The dashboard shows only the start of a key. Its **Copy** button gives you the whole key again, any time.
- You can have up to 10 active keys. A key you have just rotated keeps working for its last 24 hours on top of those. Give each key a name that says where it is used.

## Rotate a key

Rotating a key gives you a new one and keeps the old one working for 24 hours, so you have time to replace it where it is used. After that the old key stops.

## Revoke a key

Revoking a key stops it right away. Use it when a key may have leaked.

## Keep it secret

- Read the key from an environment variable or a secret store. Do not write it in code you share.
- Never call the API from a web page or a mobile app: anyone could read the key there. Call it from your server.
- Credits and limits belong to the account, not to a key. Making more keys does not raise a limit.

> **A key works without a password.** Anyone who has it can spend your credits. If you pasted one somewhere public, revoke it and create another.
