> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nextintent.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate with an API key (ni_live_...) or a console session as a Bearer token. Keys are account-wide or bound to one website, carry scopes, and are minted only by a person.

Every request except `GET /openapi.json` carries a Bearer token: an API key, or the session token of a person signed in to the NextIntent console.

```
Authorization: Bearer ni_live_YOUR_KEY
```

## API keys

* Created in the console (or with `POST /keys` from a console session). The token is shown once.
* **Account-wide or site-bound.** A bound key sees only its website: it cannot list other websites, and cannot create or delete websites.
* **Scopes:** `sites:read`, `sites:write`, `facts:read`, `facts:write`. A request outside the key's scopes answers 403.
* **Role:** `viewer` or `admin`. Keys cannot mint or revoke keys whatever their role; only a person can.
* **Expiry:** optional `expires_at`. An expired key answers 401.
* Revoke with `DELETE /keys/{key_id}`; the key stops at once.

## Console sessions

A person signed in to the console sends their session token the same way. Sessions are account-wide and are the only way to manage keys.

## Rate limits

600 requests a minute per key (or per console user). 60 a minute per IP before the token is checked, so a credential-stuffing loop is refused cheaply. Both answer 429 with a `Retry-After` header.

## Tenancy

Every website belongs to an account. A site id from another account answers 404 on every route, including the views, so a public `site_id` seen in a page's HTML gives a caller nothing.

## Storefront routes are different

The routes on `sdk.nextintent.ai` (settings, cart, card, checkout) are called by anonymous visitors' browsers and are gated by the page's `Origin` against the site's allowed list, not by a key. The order, refund and erase feeds carry the site's public key in `X-NextIntent-Token`. See [Commerce endpoints](/api/commerce-endpoints).

## Related

* [API overview](/api/reference/overview)
* [Create an API key](/api/reference/keys/create)
