> For the complete documentation index, see [llms.txt](https://www.boxhero.io/docs/llms.txt). Every page is available as Markdown by appending `.md` to its URL; this page is [Markdown](https://www.boxhero.io/docs/developers/api/authentication.md).

# Authentication

> Authenticate BoxHero API requests with a Bearer token and send them to the versioned base URL.

## API tokens

Every request must carry an API token as a Bearer token in the `Authorization` header:

```
Authorization: Bearer <api-token>
```

Issue tokens in the BoxHero app under `Settings` > `Integrations`. Each token is bound to a single team: every request reads and writes that team's data only. To work with several teams, issue a token in each of them.

Anonymous access is not supported. When the token is missing or invalid, every endpoint returns `401` with an [error envelope](https://www.boxhero.io/docs/developers/api/errors).

> **Caution**
>
> **Note**: Treat a token like a password. Keep it on your server, and if it leaks, delete it in `Settings` > `Integrations` and issue a new one.

## Base URL and versioning

All requests go to:

```
https://rest.boxhero-app.com
```

Every endpoint lives under the `/v1` prefix — for example, `GET /v1/items`.

## Team mode

Most endpoints are available only to teams that manage stock by [location](https://www.boxhero.io/docs/concepts/locations). For other teams they return `400` with the error type `/errors/invalid-team-mode`. Team, member, partner, and attribute endpoints work for every team — call [Get the linked team](https://www.boxhero.io/docs/developers/api/reference/teams/get-linked-team) to see which mode your team uses.
