# Authentication

## Getting an API Key

Create an API Key in the [Dashboard Key Management](/dashboard/keys) page. Keys are prefixed with `tr-`.

## Authentication Methods

XRToken supports two authentication formats depending on your API protocol:

### OpenAI Format

Pass via the `Authorization` header:

```
Authorization: Bearer YOUR_API_KEY
```

### Anthropic Format

Pass via the `x-api-key` header, along with the API version:

```
x-api-key: YOUR_API_KEY
anthropic-version: 2023-06-01
```

## Security Tips

- Never hardcode API Keys in client-side code
- Use environment variables to store keys
- Rotate keys regularly
- If a key is compromised, revoke it immediately in the dashboard and create a new one
