# API keys and authentication

## Get an API key

1. An admin of your Chambr account opens **Real Call Scoring** and clicks
   **API access**.
2. Click **Create API key** from the team that should receive calls sent
   without a rep. Name the key and confirm that call participants consented
   to sharing these calls with Chambr.
3. Copy the key. Chambr shows it once. Store it in your secret store (in
   Salesforce, a [Named Credential](https://developers.staging.chambr.ai/guides/salesforce.md)).

Keys look like `chambr_sk_` followed by 43 characters. An account holds up to
10 active keys.

## Authenticate

Send the key on every request:

```http
Authorization: Bearer chambr_sk_...
```

Every response has an `X-Request-Id` header. Quote it to support.

## Rotate a key

1. Create the new key from the old key's team.
2. Deploy it, then call `GET /v1/calls/{id}`. Any status except `401` means
   the key works.
3. When the old key's **Last used** stops changing, revoke it. Revoking is
   immediate. Calls already sent stay.

If the admin who created a key leaves, the key returns
`401 api_key_owner_inactive` and shows **Needs a new key**: another admin rotates it.

## Keep keys secret

Anyone holding a key can send calls for any rep in the account. Treat it like
a password.
