> ## Documentation Index
> Fetch the complete documentation index at: https://docs.marro.si/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Send your key as a bearer token, over HTTPS, from your server.

Send the key in the `Authorization` header as a bearer token: `Authorization: Bearer <key>`.

An organization API key, created in Settings → Connections → API keys. Keys start with `mk_live_`. Marro stores only a hash of a key, so it is shown once, when it is created: copy it then. Revoking a key ends its access at once. To replace a key without downtime, create the new one, switch your server to it, then revoke the old one. Changes made with a key appear on the lead’s timeline as made by the person who created the key, via the API. Scopes: `leads.read` (Read leads), `leads.write` (Create and update leads), `leads.capture` (Capture leads).

```bash theme={null}
curl "https://app.marro.si/api/v1/lead-fields" \
  -H "Authorization: Bearer $MARRO_API_KEY"
```

Requests are refused before the key is checked when:

| Status | Code | When |
| - | - | - |
| 400 | `KEY_IN_URL` | A key, or a parameter such as `api_key` or `token`, is in the URL. Keys go only in the Authorization header; replace a key that has been in a URL. |
| 403 | `HTTPS_REQUIRED` | The request was made over plain HTTP. |
| 413 | `PAYLOAD_TOO_LARGE` | The body is over 100 KB. |
| 415 | `UNSUPPORTED_MEDIA_TYPE` | A body was sent without `Content-Type: application/json`. |
| 400 | `INVALID_JSON` | The body is not valid JSON. |

If a key has ever been in a URL, a browser or a public repository, revoke it and create a new one. See [Keys and scopes](/keys-and-scopes).

A missing, wrong or expired key returns `401`; a key without the needed scope returns `403`. See [Errors](/errors).
