> ## Documentation Index
> Fetch the complete documentation index at: https://api-docs.goanagram.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> How to obtain and use an API token

The Anagram API uses **API keys** to authenticate requests. You can view and manage your API keys in [**the Anagram App**](https://provider.anagram.care/api-tokens). Click “Generate new token” and follow the instructions. If you can’t find the “API Tokens” section in the settings, please contact our support team and request to activate Public API access.

Your API keys carry many privileges, so be sure to keep them secure! Do not share your secret API keys in publicly accessible areas such as GitHub, client-side code, and so forth.

All API requests must be made over [**HTTPS**](http://en.wikipedia.org/wiki/HTTP_Secure). Calls made over plain HTTP will fail. API requests without authentication will also fail.

All API requests require bearer authentication header:

```http theme={null}
Authorization: Api <your api key>
```

`Api` is the bearer name and is case sensitive. Requests without a valid token will be denied with a `401` status and an error message:

```json theme={null}
{"detail": "Invalid authentication token."}
```

<RequestExample>
  ```Authenticated Request theme={null}
  curl --request GET \
    --url https://api.anagram.care/api/auth/v1/patients/PAT4242B/ \
    --header 'Authorization: Api B3F4242424E3FDB4242424242A9C7642'
  ```
</RequestExample>
