# Authentication

Every request carries a **content key** as a bearer token:

```text
Authorization: Bearer sfs_content_…
```

| Value | Where | Notes |
|---|---|---|
| Project ID | **Delivery** → **Connection** | Part of every URL: `/api/v1/projects/{projectId}/content`. Not a secret. |
| Content key | **Delivery** → **Content API keys** → **Create key** | Shown once. Read-only, one project, published articles only. A secret. |
| API URL | **Delivery** → **Connection** | `https://api.seoforsaas.dev` |

A content key only reads its own project's published articles. The API refuses another project, any write, or any other endpoint with `403`, and returns a draft as a missing article, `404`. Keep the key on the server anyway: anyone who has it can use up your rate limit.

- Create one key per site or environment, so you can revoke one without touching the others.
- A revoked key gets `401` everywhere within about a minute.
