> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lusha.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authenticate with the Lusha API

> Get your Lusha API key from the API dashboard and pass it in the api_key header on every request. Learn what to expect when authentication fails.

Every request to the Lusha API must include your API key. The API uses a simple key-based scheme - there are no OAuth flows or token exchanges. You pass a single header, and the server authenticates the request before processing it.

## Get your API key

<Steps>
  <Step title="Sign up or log in">
    Go to [lusha.com](https://www.lusha.com/signup/) and create an account, or log in if you already have one.
  </Step>

  <Step title="Open the API dashboard">
    Generate and retrieve your API key from the [Lusha API Dashboard](https://dashboard.lusha.com/api/manage-api-keys). Copy it to a secure location.
  </Step>
</Steps>

<Note>
  Only account admins and managers with API feature access can view the API dashboard page.
</Note>

## Authenticate requests

Pass your API key in the `api_key` header on every request to `https://api.lusha.com`. The security scheme is named `ApiKeyAuth`.

```bash theme={null}
curl --request GET \
  --url 'https://api.lusha.com/v2/person?firstName=Dustin&lastName=Moskovitz&companyDomain=lusha.com' \
  --header 'api_key: YOUR_API_KEY'
```

<Note>
  The header name is `api_key` (lowercase, with an underscore). Using a different casing or header name will cause the request to be rejected.
</Note>

## Authentication errors

If your API key is missing or invalid, the API returns a `401 Unauthorized` response:

```json theme={null}
{
  "statusCode": 401,
  "message": "Unauthorized",
  "errors": []
}
```

Check the following if you receive a `401`:

* Confirm the `api_key` header is present on the request.
* Verify you are using the correct key from the [API dashboard](https://dashboard.lusha.com/api/manage-api-keys).
* Ensure the key has not been revoked or regenerated since you last copied it.

<Warning>
  Keep your API key secret. Do not commit it to version control, embed it in client-side code, or share it publicly. If a key is exposed, regenerate it immediately from the [API dashboard](https://dashboard.lusha.com/api/manage-api-keys).
</Warning>

## Next steps

Once authentication is working, review the [rate limits](/v2/rate-limiting) to understand request quotas and how to handle `429` responses in your integration.
