> ## Documentation Index
> Fetch the complete documentation index at: https://takeprofit.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> How to create a personal API token for the Platform API in TakeProfit settings, who can create one, how to send it in the x-api-key header over REST and WebSocket, and how to revoke it.

The Platform API authenticates every request with a personal API token sent in the `x-api-key` header.

## Who can create a token

Tokens live in your account settings, under [Login & Security](https://takeprofit.com/settings/account) → **Personal API Tokens**.

API tokens are available on paid TakeProfit plans. Without a subscription that block shows **Upgrade Plan and Generate** instead of **Generate New Token**, and clicking it takes you to the plans page. If the subscription ends, all tokens of the account are revoked automatically.

## Create a token

<Steps>
  <Step title="Open token settings">
    Open [takeprofit.com/settings/account](https://takeprofit.com/settings/account), go to **Login & Security** and scroll to **Personal API Tokens**.
  </Step>

  <Step title="Name the token">
    Click **Generate New Token**, enter a name from 1 to 64 characters that tells you where the token is used, for example `research-notebook`. The **Create New Token** dialog shows the one scope the token gets, `MARKETDATA:ALL:READ` — read access to all market data available on TakeProfit.
  </Step>

  <Step title="Copy the token">
    The full token is shown **only once**, under the reminder *“Copy this token. This is your only chance to do so!”*. Tokens start with the `tpk_live_` prefix. Copy it and store it in a secret manager or an environment variable. Afterwards the list shows only a masked prefix, and a lost token cannot be recovered — create a new one.
  </Step>
</Steps>

## Send the token

Pass the token in the `x-api-key` header of every REST request:

```bash theme={null}
curl -H "x-api-key: $TAKEPROFIT_API_KEY" \
  "https://public-api.takeprofit.com/api/v1/marketdata/exchanges"
```

For WebSocket streams, send the same header on the connection handshake. Exactly one header value is accepted; duplicate or comma-separated values are rejected. Tokens in query parameters are not supported.

A request without a valid token is answered with `401`.

## Revoke a token

In **Personal API Tokens**, click **Revoke** next to the token and confirm. Requests with a revoked token fail with `401` right away. Revoke a token as soon as you suspect it leaked, then create a new one.

## Keep tokens safe

* Never put a token in client-side code, public repositories or shared notebooks.
* Use a separate token per application, so you can revoke one without breaking the others.
