# Authentication and account boundaries

Create an API key in **Developers → API Keys** while signed into the account and store you want to use. The secret is displayed at creation or regeneration. Keep it in your client’s private credential configuration.

Send one of these headers on every API request:

```http
X-API-Key: YOUR_SMSRED_API_KEY
```

```http
Authorization: Bearer YOUR_SMSRED_API_KEY
```

The same key authenticates the hosted MCP. Do not put keys in URLs, tool arguments, source control, SMS text or logs. Use HTTPS.

A key grants access to one account on one store. The server binds the account from the key; no developer request accepts an `accountId`, tenant, site or reseller selector. Use a reseller store's origin for its keys. A primary SMS.Red key is not a reseller-store key. Message requests require ownership of the associated order.

Current keys grant read, purchase and cancellation access. There are no per-key read-only scopes. Create a dedicated integration key for easy revocation. Deleting, disabling or regenerating a key invalidates its old secret; Hosted MCP authentication is checked on each request, without a shared logged-in session.

Unauthenticated or revoked keys fail authentication. A valid key presented to the wrong store also fails. Rotate the client configuration after regenerating a key.

[Documentation index](https://sms.red/docs/ai/index.md)
