# Authentication

Every Deepinfo API request is authenticated with your API key in the apikey header.

Source: https://docs.deepinfo.com/getting-started/authentication/

Last updated: 2026-10-05

---
Every request must include your API key in the `apikey` HTTP header.

```http
apikey: YOUR_API_KEY
```

The header goes on every call. A `GET` lookup:

```bash
curl "https://api.deepinfo.com/v1/lookup/whois?domain=deepinfo.com" \
  -H "apikey: YOUR_API_KEY"
```

A `POST` search with a JSON body carries the same header:

```bash
curl -X POST "https://api.deepinfo.com/v1/easm/assets/search" \
  -H "apikey: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"filters": {"must": [{"name": "asset_type", "type": "eq", "value": "domain"}]}}'
```

## Get an API Key

You create and manage API keys in the Deepinfo Platform ([platform.deepinfo.com](https://platform.deepinfo.com);
demo accounts: [platform.deepinfodemo.com](https://platform.deepinfodemo.com)),
under **Settings → Organization Settings → API Keys**. There you can generate a new key, rename a key,
choose the default key and delete a key. The Platform Guide shows each step:
[Create and manage API keys](/guide/settings/api-keys/).

No platform access? Contact [support@deepinfo.com](mailto:support@deepinfo.com).

## What Can Go Wrong

A missing or invalid key returns **401 Unauthorized**. A valid key that calls an endpoint outside your plan
returns **403 Forbidden**. See [Errors](/getting-started/errors/) for the exact responses.

| Status | Message | Cause |
|---|---|---|
| 401 | `No API key found in request` | The `apikey` header is missing |
| 401 | `Unauthorized` | The API key is not valid |
| 403 | `You cannot consume this service` | The endpoint is not included in your plan |

## Keep Your Key Secret

> [!WARNING]
> Keep your API key secret. Do not put it in client-side code or public repositories.

Call the API from your own backend and keep the key in an environment variable or a secret store. Anyone
holding the key can spend your quota and read your platform data.

If a key is exposed, replace it:

1. Generate a new key under **Settings → Organization Settings → API Keys**.
2. Switch your integration to the new key.
3. Delete the exposed key. The default key cannot be deleted, so if the exposed key is the default, set
   another key as default first.

## In Postman

The same key works in the Deepinfo [Postman collection](/getting-started/postman/). Authentication is
set once on the collection (**Authorization** tab, *API Key*), and every request inherits it from the
`{{api_key}}` variable, so you never add the header by hand. Put your key in the `api_key` variable of the
*Deepinfo - Production* environment, in **Current value**, so it stays on your machine.
