> For the complete documentation index, see [llms.txt](https://docs.roboflow.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.roboflow.com/developer/rest-api/authenticate-with-the-rest-api.md).

# Authenticate with the REST API

Most Roboflow API endpoints require an API key or OAuth access token. You can authenticate your request through the `api_key` parameter in the body and the query, via an authentication header, or with a query parameter.

For applications that authenticate on behalf of Roboflow users, see [Sign In With Roboflow (Getting Started)](/developer/authentication/sign-in-with-roboflow-getting-started.md). OAuth access tokens work with all of the authentication methods below.

### Authentication Header

We recommend you authenticate with the REST API by sending your API key as a bearer authentication header.

Here is an example of the header structure:

```
Authorization: Bearer abcdefghijklmnopqrstuvwxyz
```

### Body Parameter

You can send your API key as a parameter within a JSON request body of POST endpoints.

Here is an example of using an API key in the body of a request:

```json
{
    "api_key":"abcdefghijklmnopqrstuvwxyz"
}
```

### Query Parameter

You can also send your API key through a query parameter in the URL of your request.

We recommend against this method of authentication for production applications for security reasons. We instead recommend sending authentication headers.

Here is an example of an API key sent in a query parameter:

```
https://api.roboflow.com?api_key=abcdefghijklmnopqrstuvwxyz
```
