# auth.md — Authentication for useapi.net

> Machine- and human-readable guide to authenticating with the useapi.net API.
> useapi.net uses a long-lived, per-account **static API token** sent as a Bearer
> header. There is **no** OAuth flow, no token-exchange endpoint, and no
> agent-registration handshake — a single token authenticates every API request.

## Scheme

| Property | Value |
|---|---|
| Type | Static API token (long-lived bearer credential) |
| Transport | HTTPS only |
| API base URL | `https://api.useapi.net` |
| Auth header | `Authorization: Bearer user:TOKEN` |
| Token format | `user:<digits>-<alphanumeric>` (e.g. `user:12345-abcdefghijklmnop`) |
| Scope | One token authorizes every API under the user's subscription |

## How to authenticate

Send every request to `https://api.useapi.net` with an `Authorization` header
carrying your token, prefixed by `Bearer `:

```
Authorization: Bearer user:12345-abcdefghijklmnop
```

Notes that prevent the common `401`:

- Send the **complete** token, including the literal `user:` prefix and the
  alphanumeric suffix. Do not truncate it to just the digits.
- Do **not** URL-encode the token.
- The token is the only credential — there is no separate client id/secret,
  refresh token, or login endpoint.

### Example request

```bash
curl https://api.useapi.net/v2/account \
  -H "Authorization: Bearer user:12345-abcdefghijklmnop"
```

`GET https://api.useapi.net/v2/account` returns the account's subscription
status and configured AI-service accounts, and is the documented way to verify
that a token works.

## How a human obtains a token

A token is issued to a person, not minted programmatically by an agent:

1. Purchase a useapi.net subscription at `https://useapi.net/docs/subscription`.
   Enter a valid email — the token is delivered there.
2. Open the welcome email and follow its verification link to activate the
   account.
3. The activated page displays the account's useapi.net API token. Copy the
   complete `user:...` string.

Full walkthrough: `https://useapi.net/docs/start-here/setup-useapi`

An AI agent cannot self-register or self-provision a token. A human completes
the steps above once, then supplies the resulting token to the agent.

## What this token authorizes

A single token works across every useapi.net service API (Runway,
Kling, MiniMax / Hailuo, Google Flow, Google Vids, Gemini Notebook, Dreamina, Mureka,
FlowMusic, TemPolor, PixVerse, InsightFaceSwap, and account management). Per-API request and response
shapes differ — only the authentication header is shared.

## Discovery for agents

- API base URL: `https://api.useapi.net`
- Service index (LLM-readable): `https://useapi.net/llms.txt`
- Combined documentation: `https://useapi.net/llms-full.txt`
- Agent integration guide: `https://useapi.net/llm-tools/claude-code-skill.txt`
- API catalog (RFC 9727 linkset): `https://useapi.net/.well-known/api-catalog`
- Verify a token: `GET https://api.useapi.net/v2/account`

## Support

Questions about access or tokens: `https://useapi.net/docs/support`

