> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lusha.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authenticate with the Lusha API

> Get your Lusha API key from the API dashboard and pass it in the api_key header on every request. Learn what to expect when authentication fails.

Every request to the Lusha API must include your API key. The API uses a simple key-based scheme - there are no OAuth flows or token exchanges. You pass a single header, and the server authenticates the request before processing it.

## Get your API key

<Steps>
  <Step title="Sign up or log in">
    Go to [lusha.com](https://www.lusha.com/signup/) and create an account, or log in if you already have one.
  </Step>

  <Step title="Open the API dashboard">
    Generate and retrieve your API key from the [Lusha API Dashboard](https://dashboard.lusha.com/api/manage-api-keys). Copy it to a secure location.
  </Step>
</Steps>

<Note>
  Only account admins and managers with API feature access can view the API dashboard page.
</Note>

## Authenticate requests

Pass your API key in the `api_key` header on every request to `https://api.lusha.com`. The security scheme is named `ApiKeyAuth`.

```bash theme={null}
curl --request POST \
  --url https://api.lusha.com/v3/contacts/search-and-enrich \
  --header 'api_key: YOUR_API_KEY' \
  --header 'Content-Type: application/json' \
  --data '{
    "contacts": [
      { "firstName": "Dustin", "lastName": "Moskovitz", "companyDomain": "lusha.com" }
    ],
    "reveal": ["emails", "phones"]
  }'
```

<Note>
  The header name is `api_key` (lowercase, with an underscore). Using a different casing or header name will cause the request to be rejected.
</Note>

<Tip>
  Want to authenticate without writing code first? Import the [Lusha Postman Workspace](https://www.postman.com/lushateam/workspace/lusha-s-api/collection/28683568-fc849873-9ae1-47dd-8159-0d4deda04750), add your API key as a collection variable, and every request in the collection picks it up automatically.
</Tip>

## Authentication errors

If your API key is missing or invalid, the API returns a `401 Unauthorized` response:

```json theme={null}
{
  "statusCode": 401,
  "message": "Unauthorized",
  "errors": []
}
```

Check the following if you receive a `401`:

* Confirm the `api_key` header is present on the request.
* Verify you are using the correct key from the [API dashboard](https://dashboard.lusha.com/api/manage-api-keys).
* Ensure the key has not been revoked or regenerated since you last copied it.

<Warning>
  Keep your API key secret. Do not commit it to version control, embed it in client-side code, or share it publicly. If a key is exposed, regenerate it immediately from the [API dashboard](https://dashboard.lusha.com/api/manage-api-keys).
</Warning>

## Next steps

Once authentication is working, review the [rate limits](/rate-limiting) to understand request quotas and how to handle `429` responses in your integration.
