# Authentication

Send your account’s API key as a bearer token on every request. Your Mav team can give you your key. Keep it on your server, never in a browser or app: it can read your contacts.

The examples read it from a `MAV_API_KEY` environment variable.

```http
Authorization: Bearer YOUR_API_KEY
Content-Type: application/json
```

A missing or wrong key gets **403 Forbidden**.
