---
title: "Authentication"
description: "Authenticate your API requests using Bearer tokens."
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.svgdiagram.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

Requests to protected endpoints in the `svgdiagram.ai` REST API require authentication using an API key passed in the HTTP `Authorization` header. Public catalog and export options endpoints can be queried without credentials.

---

## API Keys

API keys are formatted with the prefix `svg_sk_`:

```text
svg_sk_1a2b3c4d5e6f7g8h9i0j...
```

You can generate and manage your API keys in your workspace settings at **[https://svgdiagram.ai/settings](https://svgdiagram.ai/settings)**.

---

## Endpoint Access

- **Public Catalog Endpoints**: `GET /rest/v1/designs`, `GET /rest/v1/designs/:id`, `GET /rest/v1/designs/:id/preview.png`, `GET /rest/v1/export-options`, and `GET /rest/v1/icons`.
- **Protected Endpoints**: Generation creation (`POST /rest/v1/generations`), diagram fetching, re-rendering, styling, and file downloads.

---

## Authorization Header

Pass your API key as an HTTP Bearer token in requests to protected endpoints:

```http
Authorization: Bearer svg_sk_your_api_key_here
```

### Request Example

```bash
curl -X POST https://svgdiagram.ai/rest/v1/generations \
  -H "Authorization: Bearer svg_sk_your_api_key_here" \
  -H "Content-Type: application/json" \
  -d '{
    "prompt": "Sequence diagram of authentication flow",
    "design": "auto"
  }'
```

> **Caution**
>
> Keep your API keys secure. Do not commit keys to public repositories or expose them in client-side browser bundles.

---

## Rate Limits & Errors

API requests are subject to per-minute rate limits configured on your account key. When a request exceeds the allowed threshold, the API responds with a `429 Too Many Requests` status code.

If a request to a protected endpoint is missing an `Authorization` header or presents an invalid API key, the API returns a `401 Unauthorized` status code:

```json
{
  "error": "Unauthorized",
  "code": "unauthorized"
}
```

Source: https://docs.svgdiagram.ai/authentication/index.mdx
