# Authentication

> Personal API keys — how to create, send, rotate and revoke them.

## Keys

Every request carries a personal API key:

```http
Authorization: Bearer bym_live_...
```

Staff create keys in bymundi under **Integrations → API & MCP**. A key:

- **acts as the person who created it.** It sees what they see and does what they may do in the app, capped at an agent's powers: a key never has admin powers, even when its owner is an admin.
- **carries [permissions](https://api.bymundi.com/docs/guides/permissions.md)** chosen when it is created.
- **is shown once.** bymundi stores only a hash; if you lose it, create another.
- **expires** after 30, 90 or 365 days, or never, as chosen at creation.
- **can be revoked** at any moment from the same screen; the next request with it answers [`401 unauthorized`](https://api.bymundi.com/problems/unauthorized.md).

`bym_live_` keys work against production. `bym_test_` keys come from test deployments and are refused by production.

The API is in early access: your agency needs API access switched on by bymundi.

## Keep keys secret

Treat a key like a password. Keep it in a secret store or an environment variable, never in a browser, a mobile app or a repository. The MCP endpoint refuses browser origins ([`origin_not_allowed`](https://api.bymundi.com/problems/origin_not_allowed.md)) for the same reason.

## Rotating

Create the new key, deploy it, then revoke the old one. Both work in between.

## Who did what

Every write is recorded with the key that made it. Staff see it under **Activity** in the same screen, filterable by key.
