> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.videogen.io/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.videogen.io/_mcp/server.

# Authentication

> Create an API key from the VideoGen dashboard, set the Authorization bearer header, and keep credentials safe with environment variables.

The VideoGen API accepts two kinds of bearer credentials: an **API key** (best when you call the API from your own backend) and an **OAuth 2.1 access token** (best when your app acts on behalf of other VideoGen users). Both are sent the same way — in the `Authorization` header — and every endpoint works identically regardless of which you use.

If you're building an integration that connects to other people's VideoGen accounts, see [Sign in with VideoGen](/oauth) for the OAuth flow. The [CLI](/libraries/cli) also supports interactive OAuth via `videogen login`. Otherwise, use an API key as described below.

## API keys

The VideoGen API uses Bearer token authentication. Include your API key in the `Authorization` header of every request:

```bash
Authorization: Bearer sk_videogen_live_...
```

### Creating a key

1. Go to [app.videogen.io/api](https://app.videogen.io/api)
2. Click **Create API key**
3. Copy the key immediately; it is only displayed once

### Keeping your key safe

Your API key is a secret. Do not expose it in client-side code (browsers, mobile apps) or commit it to version control. Use environment variables or a secrets manager instead.

```bash
export VIDEOGEN_API_KEY="sk_videogen_live_..."
```

### Making requests

**TypeScript:**

```typescript
import { VideoGen } from "@videogen/sdk";

const client = new VideoGen({
  apiKey: "sk_videogen_live_...",
});
```

**Python:**

```python
from videogen import VideoGen

client = VideoGen(api_key="sk_videogen_live_...")
```

**cURL:**

```bash
curl https://api.videogen.io/v1/files \
  -H "Authorization: Bearer sk_videogen_live_..."
```

## Error responses

If your key is missing or invalid, the API returns `401 Unauthorized`:

```json
{
  "message": "Unauthorized"
}
```