# Authentication (/docs/authentication)



Trackee authenticates protected API routes with organization-scoped access keys. Better Auth owns the keys and their organization relationship.

## Create an access key [#create-an-access-key]

1. Sign in to the [Trackee dashboard](/dashboard).
2. Create or select an organization.
3. Enter a name for the key and select **Create key**.
4. Copy the complete key. Trackee shows it only once.

## Send the key [#send-the-key]

Include the key in the `x-access-key` request header:

```bash
curl https://api.trackee.dev/v1/health/auth \
  -H "x-access-key: YOUR_ACCESS_KEY"
```

A valid key returns `{ "ok": true }`.

| Status | Meaning                                  |
| ------ | ---------------------------------------- |
| `401`  | The request has no access key.           |
| `403`  | The access key is invalid or revoked.    |
| `500`  | Trackee could not verify the access key. |

## Keep keys safe [#keep-keys-safe]

* Store keys in environment variables or a secret manager.
* Do not expose a key in browser code.
* Do not commit a key to source control.
* Use a different key for each environment.
* Revoke a key when it is no longer needed.
