> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hiveinspect.com/llms.txt
> Use this file to discover all available pages before exploring further.

# API Authentication: Create and Use Hive Inspect API Keys

> Create a Hive Inspect API key in Business Tools, send it as a Bearer token on every request, and learn who can manage keys and when a key stops working.

<p className="hive-locator">In the dashboard: <strong>Business Tools → API Access</strong></p>

<Note>
  **The Hive Inspect API is a work in progress.** It is available to a small group of accounts today, and the release for everyone is coming very soon. To ask for early access, message us from the chat bubble in your dashboard.
</Note>

Every request needs an API key. A key identifies your organization, so the API only ever returns your own data.

## Create a key

<Steps titleSize="h3">
  <Step title="Open API Access">
    Go to **Business Tools → API Access**. The page shows whether API access is enabled for your organization and what a key can do.
  </Step>

  <Step title="Create and name the key">
    Click **Create API Key** and name it after where you will use it, such as `Zapier` or `CRM sync`. A clear name tells you which key to delete later.
  </Step>

  <Step title="Copy the key">
    Copy the key and store it somewhere safe, like a password manager. Hive shows the full key only once. After that, the page lists it masked.
  </Step>
</Steps>

## Send the key

Send your key in the `Authorization` header as a Bearer token:

```bash theme={"theme":{"light":"github-light","dark":"vesper"}}
curl "https://api.hiveinspect.com/v1/inspections?limit=10" \
  -H "Authorization: Bearer YOUR_API_KEY"
```

A request with a missing or wrong key returns `401`.

## Who can manage keys

The account owner and admins can create, view and delete keys. Other team members see the API Access page without the keys.

## What a key can reach

Every key has the same permissions. It can read and change all of your organization's contacts, and read your inspections, events and stats. It can never reach another organization's data.

## When a key stops working

* **You delete it.** Anything using the key stops working within about a minute.
* **The person who created it leaves.** A key belongs to the person who created it. If they are removed from the team or lose owner or admin access, their keys stop working right away.

<Tip>
  Create one key per integration. If one tool is retired or a key leaks, you can delete that key without breaking the others.
</Tip>

## Keep keys safe

* Treat a key like a password. Never put it in a web page, a mobile app or a public code repository.
* If a key may have leaked, delete it on the API Access page and create a new one.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.