> ## Documentation Index
> Fetch the complete documentation index at: https://docs.api.dental/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Learn how to authenticate your API Dental requests using API keys.

API Dental uses API keys to authenticate all requests. You can view and manage your API keys in the [Dashboard](https://api.dental/dashboard).

## Authentication Methods

You can authenticate using either method:

### Header Authentication (Recommended)

```bash theme={null}
X-Token-API: your-api-key
```

### Bearer Token

```bash theme={null}
Authorization: Bearer your-api-key
```

## Using Your API Key

<CodeGroup>
  ```bash cURL (Header) theme={null}
  curl -X POST https://wg.api.dental/rest/Eligibility \
    -H "X-Token-API: apid_prod_..." \
    -H "Content-Type: application/json" \
    -d '{ ... }'
  ```

  ```bash cURL (Bearer) theme={null}
  curl -X POST https://wg.api.dental/rest/Eligibility \
    -H "Authorization: Bearer apid_prod_..." \
    -H "Content-Type: application/json" \
    -d '{ ... }'
  ```

  ```typescript TypeScript SDK theme={null}
  import APIDental from 'api-dental';

  const client = new APIDental({
    apiKey: process.env['API_DENTAL_API_KEY'],
  });
  ```

  ```csharp C# SDK theme={null}
  using APIDentalPro;

  APIDentalProClient client = new() { APIKey = "apid_prod_..." };
  ```
</CodeGroup>

<Warning>
  **Keep your API keys secure!** Do not share your secret API keys in publicly accessible areas such as GitHub, client-side code, or public repositories.
</Warning>

## Security Validation

Every API request passes through a 7-layer security validation:

```mermaid theme={null}
flowchart TD
    A[Incoming Request] --> B{1. Authentication}
    B -->|Invalid/Missing Key| B1[401 Unauthorized]
    B -->|Valid| C{2. API Key Status}
    C -->|Disabled| C1[403 Forbidden]
    C -->|Active| D{3. Active Subscription}
    D -->|None| D1[402 Payment Required]
    D -->|Active| E{4. Billing Sync}
    E -->|Error| E1[500 Internal Error]
    E -->|OK| F{5. Payment Method}
    F -->|Missing| F1[402 Payment Required]
    F -->|Present| G{6. Trial Status}
    G -->|Expired| G1[401/402 Trial Expired]
    G -->|Valid| H{7. Rate Limiting}
    H -->|Exceeded| H1[429 Rate Limited]
    H -->|OK| I[Request Processed]
```

| Layer | Check | Error Code |
| - | - | - |
| 1 | Authentication — valid API key | 401 |
| 2 | API Key Status — not disabled | 403 |
| 3 | Active Subscription — plan exists | 402 |
| 4 | Billing Data Sync — data consistent | 500 |
| 5 | Payment Method — card on file (trial users) | 402 |
| 6 | Trial Status — not expired | 401/402 |
| 7 | Rate Limiting — within plan limits | 429 |
