> ## Documentation Index
> Fetch the complete documentation index at: https://docs.storerocket.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Create a token, choose permissions, and authenticate requests.

## Create a token

Open [API Tokens](https://storerocket.io/app/api-tokens), create a token, and copy it securely. The full token is shown only when it is created.

The token belongs to your user account and can access projects that account belongs to. Location endpoints also check the project's API access and the token's permissions.

## Send the token

<CodeGroup>
  ```bash cURL theme={null}
  curl 'https://storerocket.io/api/v2/projects' \
    -H 'Authorization: Bearer YOUR_TOKEN' \
    -H 'Accept: application/json'
  ```

  ```javascript JavaScript theme={null}
  const token = process.env.STOREROCKET_TOKEN;
  if (!token) throw new Error("Set STOREROCKET_TOKEN first.");

  const url = new URL(`https://storerocket.io/api/v2/projects`);
  const response = await fetch(url, {
    headers: {
      Authorization: `Bearer ${token}`,
      Accept: "application/json",
    },
    signal: AbortSignal.timeout(30_000),
  });

  const text = await response.text();
  if (!response.ok) throw new Error(`HTTP ${response.status}: ${text}`);
  console.log(JSON.parse(text));
  ```

  ```php PHP theme={null}
  <?php

  $token = getenv("STOREROCKET_TOKEN") ?: throw new RuntimeException("Set STOREROCKET_TOKEN first.");

  $url = 'https://storerocket.io/api/v2/projects';

  $curl = curl_init($url);
  curl_setopt_array($curl, [
      CURLOPT_HTTPHEADER => [
          "Authorization: Bearer $token",
          "Accept: application/json",
      ],
      CURLOPT_RETURNTRANSFER => true,
      CURLOPT_CONNECTTIMEOUT => 5,
      CURLOPT_TIMEOUT => 30,
  ]);

  $text = curl_exec($curl);
  $error = curl_error($curl);
  $status = (int) curl_getinfo($curl, CURLINFO_HTTP_CODE);
  curl_close($curl);

  if ($text === false) {
      throw new RuntimeException("Request failed: $error");
  }
  if ($status < 200 || $status >= 300) {
      throw new RuntimeException("HTTP $status: $text");
  }
  $data = json_decode($text, false, 512, JSON_THROW_ON_ERROR);
  echo json_encode($data, JSON_PRETTY_PRINT | JSON_THROW_ON_ERROR), PHP_EOL;
  ```
</CodeGroup>

Use `Authorization: Bearer`, not an `X-API-Key` header or a token in the URL. Keep tokens in server-side integrations and out of public website code.
For JSON request bodies, also send `Content-Type: application/json`.

JavaScript examples run in Node.js 22 or later; PHP examples require PHP 8.2 or later with cURL. Both read `STOREROCKET_TOKEN` from your environment. See the [quickstart](/api/quickstart) for setup.

## Location permissions

| Permission | Methods |
| - | - |
| `location:read` | GET location list and GET one location |
| `location:create` | POST location |
| `location:update` | PATCH and PUT location |
| `location:delete` | DELETE location |

Select the permissions your integration needs when creating its token. Revoke an unused or compromised token from the same API Tokens page.

## Authentication errors

A missing, expired, revoked, or invalid token returns `401`:

```json theme={null}
{"message":"Unauthenticated."}
```

A valid token without the required permission, or a project without API access, returns `403`. A project or location outside your access returns `404`. See [errors](/api/errors).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.