> ## Documentation Index
> Fetch the complete documentation index at: https://docs.endl.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate every Partner API request with your key and secret

Every request to `/api/v0/**` carries two headers.

| Header         | Value                                                  |
| -------------- | ------------------------------------------------------ |
| `X-API-KEY`    | Your partner API key, which identifies the credential. |
| `X-API-SECRET` | Your partner API secret, compared in constant time.    |

```bash theme={null}
curl https://qa-api.endl.xyz/api/v0/currencies \
  -H "X-API-KEY: $ENDL_API_KEY" \
  -H "X-API-SECRET: $ENDL_API_SECRET"
```

<Warning>
  Keep your secret server-side. Never ship it in browser or mobile code, and never commit it to source control. If it leaks, ask Endl to issue a replacement credential.
</Warning>

## Permissions

Each key carries permissions that gate which endpoints it can reach — `quotes`, `recipients`, `accounts`, `webhooks`, and `events` among them.

A valid key that lacks the required permission is rejected with `400 VALIDATION_ERROR`, **not** `403`. If a well-formed call fails validation for no apparent reason, check the key's permissions before you check the body.

## Failure modes

<ResponseField name="401 UNAUTHORIZED" type="Your credentials were rejected">
  A header is missing or blank, the key is unknown, the secret is wrong, or the partner is inactive. These are indistinguishable by design. Retrying will not help — fix the configuration.
</ResponseField>

<ResponseField name="503 DIRECTORY_UNAVAILABLE" type="Endl could not verify right now">
  Endl could not reach the credential store. Your key may be perfectly valid, so retry with backoff. This is deliberately not a `401`.
</ResponseField>

<Note>
  Webhook endpoints use these same two headers. See [webhooks authentication](/webhooks/authentication) for the `webhooks` and `events` permissions specifically.
</Note>
