# Authentication

Keys, and what works without one.

HTML version: https://dyme.earth/affiliates/build/authentication

Send your key in the `Authorization` header:

```http
Authorization: Bearer dyme_live_YOUR_KEY
```

The same key works for the [MCP server](https://dyme.earth/affiliates/build/mcp).

## Without a key

You can call the API without a key, at 30 requests an hour per IP address. That works from a browser too, since responses carry `Access-Control-Allow-Origin: *`. Links in keyless responses don't carry an affiliate code, so nobody is credited for bookings from them. It's for trying things out.

## Getting a key

Apply at [dyme.earth/affiliates](https://dyme.earth/affiliates); approved affiliates can ask for an API key. Keys come at the standard tier (2,000 requests a day). If you need more, say so and we'll set you up on the partner tier (20,000 a day).

A key looks like `dyme_live_` followed by 32 characters.

## Keeping it safe

- Keep the key on your server, in a secret or an environment variable.
- Don't put it in client-side code, in a widget address, or in a public repository. Widgets don't take a key at all, only your affiliate code.
- If a key leaks, email us and we'll issue a new one and revoke the old one.

If a key we don't recognise, or one that's been revoked, is sent, the request isn't refused. It's served as if there were no key: the keyless limit applies and links carry no affiliate code. The response header `X-Dyme-Key-Status` says why.

## Errors

Errors are JSON with a `code` and a `message`:

```json
{ "error": { "code": "rate_limited", "message": "…" } }
```

| Status | Code | Meaning |
|---|---|---|
| `400` | `invalid_params` | A required parameter is missing or wrong. |
| `404` | `not_found` | No hotel or place matched. |
| `429` | `rate_limited` | You're over the limit. See [rate limits](https://dyme.earth/affiliates/build/limits). |
