# StellarFirm API authentication

> How authentication works for the StellarFirm API. Which routes need no sign-in, which need a signed-in account, and how to send the session as a Bearer token or a cookie.

Some StellarFirm API routes are public and some belong to an account. This page says which is which and how to send the session to the ones that need it.

## Public routes

These need no sign-in and no header:

- `GET /api/health`
- `GET /api/site-banner`
- `POST /api/email/unsubscribe`, which is protected by the signed token in the link instead

## Account routes

These answer for the signed-in account:

- `GET /api/entitlement`
- `GET /api/credits/balance`

Without a session they answer `401` with the error code `signed_out`. See [Errors](/docs/api/errors).

## How to send the session

There are two ways, and the OpenAPI file names both as security schemes.

| Scheme | How | Who uses it |
| --- | --- | --- |
| `bearerAuth` | `Authorization: Bearer <session token>` | The desktop app, the phone app, and a program acting for an account |
| `sessionCookie` | The `__session` cookie | A browser after you sign in at [/sign-in](https://stellarfirm.ai/sign-in) |

The session token belongs to a signed-in StellarFirm account. It is short lived and tied to that account, so a program has to be given one by the person whose account it is.

> [!IMPORTANT]
> StellarFirm does not issue long-lived developer tokens today, and self-service sign-up is not open yet. A program cannot create an account or sign itself in. Accounts are created from a waitlist invitation. See [Sign in](/docs/getting-started/sign-in).

## Keep the session private

- Send the token only over HTTPS, and only to `https://stellarfirm.ai`.
- Never paste a session token into a chat, an issue, or a log.
- A token that stops working answers `401`. Sign in again to get a new one.

## What the session can do

The API routes only read. A session cannot make an assistant send, publish, deploy, or charge. Those steps wait for the CEO's Approve in the app.

## Related

- [Endpoints](/docs/api/endpoints)
- [Example requests](/docs/api/examples)

---

Source: https://stellarfirm.ai/docs/api/authentication
