> ## Documentation Index
> Fetch the complete documentation index at: https://veryfront.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Choose credentials and understand resource permissions.

Send a bearer token or Veryfront API key with authenticated requests. Each endpoint lists its accepted credentials and required permissions.

## Bearer tokens and API keys

Send either credential in the `Authorization` header:

```http title="request.http" theme={null}
Authorization: Bearer <token-or-api-key>
```

For an API key, you can also use the `X-API-Key` header:

```http title="request.http" theme={null}
X-API-Key: <api-key>
```

Use the [API key endpoints](/docs/cloud/rest/apis/identity-and-access-api#api-keys) to manage keys. Use the [authentication endpoints](/docs/cloud/rest/apis/identity-and-access-api#authentication) for supported sign-in and token flows.

Some endpoints require a signed-in user and reject API keys. Check the endpoint’s Authentication section before choosing a credential.

## Resource permissions

Authentication identifies the caller. Resource permissions determine which projects, conversations, runs, and other resources the caller can use.

A project-bound credential cannot access another project. Project access does not automatically grant access to every private conversation. Endpoints can also restrict actions by role or token scope.

Manage access through [account members](/docs/cloud/rest/apis/identity-and-access-api#account-members), [project members](/docs/cloud/rest/apis/identity-and-access-api#project-members), and the relevant resource permissions.

## Runtime credentials

Runtime integrations publish events and report execution outcomes with credentials bound to their permitted work. For example, a run event-writer token authorizes event publication for its bound run.

Read the authentication requirements for the [run endpoint](/docs/cloud/rest/apis/execution-api#runs) before using a runtime credential. Access to a run alone does not authorize every runtime operation.

## Anonymous access

Some catalogs and metadata endpoints allow anonymous requests. Public endpoints can still require authentication.

## Other interfaces

GraphQL, MCP, and WebSocket use their own request or connection contracts. See [GraphQL, MCP, and streaming](/docs/cloud/rest/protocols) for entry points and protocol references.

[Back to REST API reference](/docs/cloud/rest)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.