> ## Documentation Index
> Fetch the complete documentation index at: https://docs.powerdialer.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Every request carries the shared API key and the PowerDialer user it acts for.

Every request carries two things: the shared API key, and the PowerDialer user the request acts for.

| Header | Value | Required |
| - | - | - |
| `Authorization` | `Bearer <api key>` — or send the key as `x-api-key: <api key>` | Yes |
| `x-user-email` | Login email of the PowerDialer user, e.g. `rep@company.com` | One of the two |
| `x-user-id` | Clerk user id of the PowerDialer user, e.g. `user_2abc...` | One of the two |
| `Content-Type` | `application/json` on `POST` and `PATCH` | When sending a body |

The user is looked up in PowerDialer's identity provider on each request and cached for five minutes. All reads and writes are then limited to lists that user owns. If both user headers are sent, `x-user-id` wins.

```bash theme={null}
curl "https://api.migration.powerdialer.ai/api/public/v1/analytics/summary" \
  -H "Authorization: Bearer $API_KEY" \
  -H "x-user-email: rep@company.com"
```

<Warning>
  **Keep the key on your server.** Anyone holding it can act for any user. Never embed it in a browser, mobile app or client-side code. Ask PowerDialer to rotate it if it is ever exposed — two keys can be valid during a rotation.
</Warning>

## Authentication errors

| Situation | Status | Body |
| - | - | - |
| No key | `401` | `{"error":"Missing API key","details":"Send it as 'Authorization: Bearer <key>' or 'x-api-key: <key>'"}` |
| Wrong key | `401` | `{"error":"Invalid API key"}` |
| Key but no user header | `400` | `{"error":"Missing user","details":"Send the PowerDialer user as 'x-user-id: user_...' or 'x-user-email: <email>'"}` |
| User not found | `404` | `{"error":"User not found"}` |
| Identity provider unreachable | `502` | `{"error":"Failed to verify user"}` |
| API disabled on the server | `503` | `{"error":"Public API is not enabled", ...}` |

<Info>
  A `502` is transient — retry later. A `404 User not found` means the email or id does not match a PowerDialer account; check the spelling or use the other header.
</Info>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.