> ## Documentation Index
> Fetch the complete documentation index at: https://docs.marro.si/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting started

> Create an API key and make your first request.

<Steps>
  <Step title="Create a key">
    An organization administrator opens **Settings → Connections → API keys → New key**.

    * For a website or landing-page form, choose **Website form**. That key can only capture leads.
    * For any other application, choose the scopes it needs. See [Keys and scopes](/keys-and-scopes).

    Copy the key as soon as it is shown. Marro cannot show it again.
  </Step>

  <Step title="Keep it on your server">
    Store the key as an environment variable on your server, for example `MARRO_API_KEY`. Never put it in browser JavaScript, a mobile app or a URL.
  </Step>

  <Step title="Make a request">
    Send the key in the `Authorization` header as a bearer token: `Authorization: Bearer <key>`.

    An organization API key, created in Settings → Connections → API keys. Keys start with `mk_live_`. Marro stores only a hash of a key, so it is shown once, when it is created: copy it then. Revoking a key ends its access at once. To replace a key without downtime, create the new one, switch your server to it, then revoke the old one. Changes made with a key appear on the lead’s timeline as made by the person who created the key, via the API. Scopes: `leads.read` (Read leads), `leads.write` (Create and update leads), `leads.capture` (Capture leads).

    ```bash theme={null}
    curl "https://app.marro.si/api/v1/lead-fields" \
      -H "Authorization: Bearer $MARRO_API_KEY"
    ```

    Requests are refused before the key is checked when:

    | Status | Code | When |
    | - | - | - |
    | 400 | `KEY_IN_URL` | A key, or a parameter such as `api_key` or `token`, is in the URL. Keys go only in the Authorization header; replace a key that has been in a URL. |
    | 403 | `HTTPS_REQUIRED` | The request was made over plain HTTP. |
    | 413 | `PAYLOAD_TOO_LARGE` | The body is over 100 KB. |
    | 415 | `UNSUPPORTED_MEDIA_TYPE` | A body was sent without `Content-Type: application/json`. |
    | 400 | `INVALID_JSON` | The body is not valid JSON. |
  </Step>
</Steps>

Next: [Connect a website](/guides/connect-a-website) or browse the [API reference](/api-reference/leads/list-leads).
