> ## Documentation Index
> Fetch the complete documentation index at: https://docs.collabos.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate data API requests with CollabOS API keys.

All `/api/v1/...` requests require a CollabOS API key.

## Recommended: Bearer authentication

```http theme={null}
Authorization: Bearer co_u_...
```

Workspace keys use the same header:

```http theme={null}
Authorization: Bearer co_w_...
```

## Alternative: X-API-Key

```http theme={null}
X-API-Key: co_u_...
```

If both headers are present, CollabOS uses the `Authorization` Bearer value.

## Personal and workspace keys

| Key type | Prefix | Can access |
| - | - | - |
| Personal | `co_u_` | Personal profile, published public raffles, the key owner's entries and wins, native entry actions |
| Workspace | `co_w_` | Data belonging to one workspace: raffles, entries, winners, projects |

A personal key cannot be used on a workspace-only endpoint, and a workspace key cannot be used on a personal-only endpoint.

## Example request

```bash theme={null}
curl "https://api.collabos.app/api/v1/me" \
  -H "Authorization: Bearer $COLLABOS_API_KEY"
```

## Management authentication

Routes under `/api/developer/...` are different. They use the authenticated CollabOS dashboard/session JWT, not a developer API key. These routes create and revoke API keys and manage webhook endpoints.

<Warning>
  Never expose a CollabOS API key in browser JavaScript, public source code, logs, or client-side applications. Keep it on a trusted server.
</Warning>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.