# Authentication

Every API entry point into the Anantis platform authenticates with an **API key**. One key works for both the [REST API](/docs/api/) and the [MCP server](/docs/api/mcp-server/).

---

## Create an API key

1. Log in to the **Anantis Console**.

2. Navigate to **Settings → Configuration → API Keys**.

3. Click **Create API Key**.

4. Give the key a **name** that identifies where it will be used.

5. Select the **scopes** the key requires. Grant only what the integration actually calls. See [Scopes](#scopes) below.

6. Click **Create**, then copy the key.

**The key is shown once:** The full key value is displayed **only at creation time**. Once you close the dialog it cannot be retrieved, the platform stores only a hash of the key, never the key itself.

If you lose it, revoke the key and create a new one.

## Key format

Anantis API keys are prefixed so they are recognisable in logs, code review, and secret scanners:

```text
anantis_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
```

Treat the whole string as a secret. **Never** commit it to a repository, or paste it into a support ticket.

## Authenticate a request

Pass the key as a **bearer token** in the `Authorization` header:

```bash
curl https://api.anantis.io/v1/me \
  -H "Authorization: Bearer anantis_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
```

The base URL for every REST endpoint is:

```text
https://api.anantis.io/v1
```

## Verify a key

`GET /me` enables you to confirm a key works and to inspect what it can reach. It requires no scope:

```bash
curl https://api.anantis.io/v1/me \
  -H "Authorization: Bearer $ANANTIS_API_KEY"
```

```json
{
  "entity_uuid": "22222222-2222-2222-2222-222222222220",
  "key_id": "019fdde2-9021-74b9-8eae-e42eae2fdb58",
  "scopes": ["threats:read", "interactions:read", "reports:read"],
  "accessible_entities": ["22222222-2222-2222-2222-222222222220"]
}
```

| Field | Meaning |
| --- | --- |
| `entity_uuid` | The organization the key belongs to. |
| `key_id` | Identifier of the key. Safe to log, useful for support and audit. |
| `scopes` | Permissions actually granted at creation. |
| `accessible_entities` | Every organization uuid this key can address. |

## Scopes

Scopes are selected per key at creation and cannot be changed after creation.

| Scope | Grants |
| --- | --- |
| `threats:read` | List and read threats. |
| `threats:write` | Update a threat's triage status and notes. |
| `interactions:read` | List and read interactions captured by decoys. |
| `decoys:read` | List and read decoys, including their breadcrumbs. |
| `decoys:update` | Trigger a decoy software update. |
| `decoys:delete` | Decommission a decoy. |
| `canaries:read` | List and read canaries. |
| `canaries:write` | Create and update canaries. |
| `canaries:delete` | Decommission a canary. |
| `reports:read` | Export the executive report. |
| `users:read` | List and read console users. |
| `users:write` | Create console users. |
| `users:delete` | Delete console users. |

**Grant the minimum:** Most integrations are read-only (a dashboard, an MCP client, etc..). Reserve `users:*` and the `*:delete` scopes only for necessary cases.

## Next steps

- [Configure the MCP server](/docs/api/mcp-server/) to query your platform from Claude, Cursor, VS Code, and other MCP clients.
- [Browse the REST API reference](/docs/api/) for the full endpoint catalogue.