> For the complete documentation index, see [llms.txt](https://docs.zapiet.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.zapiet.com/zapiet-rates-by-zip-code/authentication.md).

# Authentication

Request an API key and send the required headers with every request.

## Get an API key

{% stepper %}
{% step %}

### Request a key

Go to [zapiet.com](https://zapiet.com) and open the chat in the bottom corner of the page. Ask for a Rates by Zip Code API key and tell us your shop's `.myshopify.com` domain.
{% endstep %}

{% step %}

### Copy it straight away

The key is shown once. It cannot be retrieved later.
{% endstep %}

{% step %}

### Store it as a secret

Keep it on your server, for example in an environment variable or a secrets manager.
{% endstep %}
{% endstepper %}

Keys start with `dbz_`. Each key belongs to one shop. You cannot quote another shop with your key.

## Required headers

Send these on every request:

| Header          | Value                                                                      |
| --------------- | -------------------------------------------------------------------------- |
| `Authorization` | `Bearer dbz_your_key_here` (or use `X-Api-Key: dbz_your_key_here` instead) |
| `Content-Type`  | `application/json`                                                         |
| `Accept`        | `application/json`                                                         |

{% hint style="warning" %}
**Don't skip `Accept: application/json`.** Without it, validation errors come back as a redirect and rate-limit errors as an HTML page, instead of JSON.
{% endhint %}

A missing, unknown or revoked key returns `401`:

```json
{ "message": "Unauthenticated." }
```

## Lost or leaked keys

Message us through the chat on [zapiet.com](https://zapiet.com) to rotate or revoke your key. When a key is rotated or revoked, the old key stops working immediately, so update your server before or straight after the change.

## Optional shop check

If one backend talks to more than one store, send `shop` (for example `your-store.myshopify.com`) in the request body. If it does not match the key's shop, the API returns `422` with `The shop does not match this API key.`
