--- title: "Authentication" --- To authenticate requests with Infisical, you must include an API key in the `X-API-KEY` header of HTTP requests made to the platform. You can obtain an API key in User Settings > API Keys ![API key dashboard](../../images/api-key-dashboard.png) ![API key in personal settings](../../images/api-key-settings.png) ![Adding an API key](../../images/api-key-add.png) It's important to keep your API key secure, as it grants access to your secrets in Infisical. For added security, set a reasonable expiration time and rotate your API key on a regular basis.