> ## Documentation Index
> Fetch the complete documentation index at: https://docs.continuouslabs.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Send an API key as a Bearer token to /v1 routes and a Simulation token to a Simulation endpoint.

## API keys

Send a Continuous API key on every `/v1` operation:

```text theme={null}
Authorization: Bearer <API key>
```

There is one security scheme and no scopes or roles. A key resolves to exactly one workspace, so no workspace header is needed. Lists and reads return that workspace's resources plus the Continuous catalog Simulators; catalog Simulators cannot be changed or deleted (`403 auth_forbidden`).

Create API keys in [the app](https://app.continuouslabs.ai) under **Settings**, then **API keys**. Key management has no public API.

See [Errors](/api-reference/errors) for authentication failures and recovery.

## Simulation tokens

Send a Simulation token to the Simulation's data-plane `endpoint`:

```text theme={null}
X-Continuous-Simulation-Token: <token>
```

The token never authenticates a `/v1` route. Create and fork return a token once, valid for one hour; later reads omit it. Mint more with `POST /v1/simulations/{id}/tokens` (the generated token endpoint lists the `ttl_seconds` range); other unexpired tokens stay valid.

A missing or rejected token answers `401 auth_invalid` with the response header `X-Continuous-Simulation-Token-Rejected: true`. A stopped Simulation answers `409 simulation_stopped` before the token is checked.

See [Send requests to a Simulation](/concepts/data-plane) for the other data-plane responses.
