> ## Documentation Index
> Fetch the complete documentation index at: https://docs.paubox.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Email API authentication

> Find your Paubox Email API key and pass it in requests with the Bearer or legacy Token authorization header, plus best practices for key rotation.

Every request to the Paubox Email API must include your API key in the `Authorization` header. Keys are managed from the [Paubox Email API > API Keys](https://next.paubox.com/settings/api_keys) page.

## Find your credentials

<Steps>
  <Step title="Open API Keys">
    Go to [Paubox Email API > API Keys](https://next.paubox.com/settings/api_keys).
  </Step>

  <Step title="Generate an API key">
    Click **Add API Key**, give it a description, and save. Copy the key immediately; it is displayed only once.
  </Step>

  <Step title="Note the base URL">
    All Email API requests go to the same base URL:

    ```
    https://api.paubox.com/v1/email
    ```
  </Step>
</Steps>

## Pass credentials in requests

Include the `Authorization` header with every API call:

```bash theme={null}
curl --request POST \
  --url https://api.paubox.com/v1/email/messages \
  --header 'Authorization: Bearer YOUR_API_KEY' \
  --header 'Content-Type: application/json'
```

### Bearer format (preferred)

```
Authorization: Bearer YOUR_API_KEY
```

### Legacy Token format (also accepted)

```
Authorization: Token token=YOUR_API_KEY
```

Both formats are accepted. New integrations should use Bearer.

## Key rotation

* Generate a new key before revoking an old one to avoid downtime.
* Each domain can have multiple active keys, which is useful for rotating across services independently.
* Revoke keys immediately if they are exposed or a team member with access leaves.

<Warning>
  Never commit API keys to source control. Use environment variables or a secrets manager to inject credentials at runtime.

  ```bash theme={null}
  # Good
  export PAUBOX_API_KEY=your_api_key
  curl -H "Authorization: Bearer $PAUBOX_API_KEY" ...

  # Bad: do not do this
  curl -H "Authorization: Bearer sk_live_abc123..." ...
  ```
</Warning>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.