# Authentication

The Whaly API uses Service Account Secret Keys to authenticate requests. You can view and manage your Secret keys in your Whaly settings panel.

Secret keys have the prefix `sk` . In order to grant proper access control to your Secret Keys, you should manage the roles and sharings of the attached Service Account.

{% hint style="warning" %}
Your Secret keys carry many privileges, so be sure to keep them secure! Do not share your secret API keys in publicly accessible areas such as GitHub, client-side code, and so forth.
{% endhint %}

Authentication to the API is performed via **HTTP Bearer Auth**. Provide your Secret key as the Bearer value in your Authorization header.

Example of curl option would be `-H "Authorization: Bearer sk:4eC39HqLyjWDarjtT1zdp7dc"`&#x20;

All API requests must be made over [HTTPS](http://en.wikipedia.org/wiki/HTTP_Secure). Calls made over plain HTTP will fail. API requests without authentication will also fail.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://developers.whaly.io/authentication.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
