# Authentication

> Server requests use a bearer token created in the VenueGo portal. The token is shown once.

Canonical page: https://venuego.co.uk/docs/authentication

Send the key on every request:

```http
Authorization: Bearer vm_live_...
```

Keys look like `vm_live_…` or `vm_test_…`. Both call the same production API. The prefix is there so you can tell a key's purpose in your own systems. VenueGo stores only a hash. If you lose a key, revoke it and create another.

Create and revoke keys under Developers in the portal. Treat the key like a password: keep it on your server, not in a mobile app, a front-end bundle, or a ticket email.

## A missing or revoked key

The response is `401` with this body:

```json
{
  "error": {
    "code": "unauthenticated",
    "message": "This API token is invalid or has been revoked."
  }
}
```

There is no session cookie on `/api/v1`. Browser logins are a different surface and cannot call these routes.

## Where the key is allowed

- Your backend, when creating, reading, or cancelling a session.
- A secret store or environment variable on that server.

Do not send the key from the guest's phone. The guest uses the `url` from the create response, which is already scoped to that one session.
