# Authentication (/authentication)



## Developer API keys [#developer-api-keys]

Create a developer API key from your CSFloat profile at
[csfloat.com/profile](https://csfloat.com/profile).

Send the key directly in the `Authorization` header. It is not a bearer token, so no scheme prefix
is used.

```http
Authorization: YOUR_API_KEY
```

## Unauthenticated requests [#unauthenticated-requests]

Public routes accept requests without an `Authorization` header. Protected routes reject them with
code `27`:

```json
{
  "code": 27,
  "message": "authorization not set"
}
```

## Security schemes [#security-schemes]

* `ApiKeyAuth` sends the developer key in the `Authorization` header.
* An empty security array means the operation needs no credentials.
