# Get an API Key

Every request to the Sail API must include an API key in the `Authorization` header. This page explains how to get your keys,how scopes work, and how to use keys in your requests.

## Request API keys

Reach out to the Sail technical team through your dedicated Slack channel to request API keys.

## Base URL

All API requests use the following base URL:

```
https://live.savewithsail.com/api/v1
```

## Authenticate your request

Include your API key as a Bearer token in the `Authorization` header on every request.

```bash
curl -X GET https://live.savewithsail.com/api/v1/users \
  -H "Authorization: Bearer sk_live_..."
```

## Key scopes

## Key scopes

Each API key has a fixed set of scopes that control which endpoints it can access. You use the same key on every request, and Sail checks whether that key's scopes cover the endpoint you're calling. If not, the API returns `403 insufficient_key_scope`.

The Sail team will work with you during implementation to determine the right scopes for your keys. You can request multiple keys with different scopes so that each part of your system only has access to what it needs.

| Scope             | Description                                                                           |
| :---------------- | :------------------------------------------------------------------------------------ |
| `expenses`        | Read expense data and create related connections (cards, merchants).                  |
| `benefit_account` | Create HSA/FSA connections and read account data (balances, activity, contributions). |
| `account_numbers` | Access ACH deposit account and routing numbers.                                       |
| `identity`        | Access personal information (PII) for users and account owners.                       |
| `ingest`          | Push your own transaction data to a connection for classification.                                                                    |
| `token_admin`     | Create and revoke short-lived tokens needed to access PII endpoints.                  |

<Callout type="warning">
  **`token_admin`**&#x20;is exclusive**

  A key with the `token_admin` scope cannot hold any other scope. This is enforced at key creation. The minting key can create tokens but can't use them to access data. A separate workload key presents the token to PII endpoints. This ensures that reaching PII always needs two credentials from two deployment contexts.
</Callout>

## Scope recommendations by integration path

The scopes you need depend on which [integration path](/docs/get-started/intro) you're following.

| Integration path   | Scopes                                           |
| :----------------- | :----------------------------------------------- |
| Expenses           | `expenses`                                       |
| Classification     | `expenses`, `ingest`                             |
| Account connection | `benefit_account`, `account_numbers`, `identity` |

If you're using PII endpoints (`identity`, `account_numbers`), you also need a separate key with the `token_admin` scope to mint ephemeral user tokens. See [Authentication](/docs/api-reference/authentication) for more on ephemeral tokens.

## Next steps

- See [Create a user](/docs/get-started/get-started-overview/create-a-user) to create your first user.