---
updatedAt: 2026-09-02T08:15:27.000Z
agentTools:
  projectIndex: https://developer.wafeq.com/llms.txt
---

# Authentication

Wafeq supports authentication via two methods,

* Private Key (recommended for accessing your own organization by your application)
* OAuth Flow (recommended for building public third party integrations with Wafeq)

# Authenticating API calls via API Key (Private Key)

To use private key authentication you will need to [Get your API Key](https://developer.wafeq.com/reference/get-your-api-key) from your [Wafeq Developer console](https://app.wafeq.com/c/api-keys).

When making an API call to a Wafeq endpoint, you must use an `Authorization` header with `Api-Key` prefix followed by your API key.

Example,

```Text curl
curl --location \
--request GET 'https://api.wafeq.com/v1/organization/' \
--header 'Authorization: Api-Key <api_key>' \
...
```

# Authenticating API calls via Access Token (OAuth2 Flow)

The OAuth2 flow allows you to create public apps that anyone can use.

To use OAuth2 flow authentication, [log in to the Wafeq Developer Portal](https://developer.wafeq.com/d/) and create an app. The portal will issue the `client_id` and `client_secret` you need for the authorization flow. Store the client secret securely; it is shown only when issued.

When making an API call to a Wafeq endpoint, you must use an `Authorization` header with `Bearer` prefix followed by the access token obtained by the OAuth flow.

Example,

```
curl --location \
--request GET 'https://api.wafeq.com/v1/organization/' \
--header 'Authorization: Bearer <access_token>' \
...
```

or you can visit [oauth2-client-examples](https://gitlab.com/wafeq-com/oauth2-client-examples) repository for demo apps implementing oauth flow with Wafeq.