> For the complete documentation index, see [llms.txt](https://developers.tix.xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developers.tix.xyz/integration-guides/authentication.md).

# Authentication and environments

Call TDP from your backend over HTTPS. Authenticate API requests with the `x-api-key` header. API keys are server-side credentials, not publishable browser keys.

Follow [Get started](/getting-started/readme.md) to create a read-only sandbox key and make your first request.

## Choose the environment

Sandbox and production are separate hosts with separate keys; a key only works on its own host. See [Environments](/getting-started/overview.md#environments) for the URLs and what differs between them. Production transactions move real funds and tickets; use a production key only after onboarding with your TDP representative.

## Grant only the permissions you need

The key-creation form initially selects all permissions. Deselect the permissions your integration does not need.

* **Query Solana:** read events, active listings, and account data. This is the only permission needed for discovery.
* **Create listings:** authorize listing creation instructions.
* **Cancel listings:** authorize listing cancellation instructions.
* **Accept offers:** authorize offer acceptance, including purchases into claim wallets.
* **Post integrator metadata:** write integrator event metadata.

A permission grants access to an operation; it does not bypass ticket ownership, resale eligibility, or transaction validation. Purchases also need a registered integrator with a funded treasury; see [How money moves](/integration-guides/secondary-resale.md#how-money-moves).

## Protect credentials

* Store deployed keys in your infrastructure's secret manager and inject them into the backend at runtime.
* Use separate keys for environments and services so access can be revoked independently.
* Never include keys in frontend bundles, mobile apps, source control, URLs, analytics, screenshots, or support messages.
* Redact authentication headers in application, proxy, and error logs.
* Treat claim URLs as private credentials too; only disclose them through the intended recipient flow.

If a key is exposed, revoke it in the dashboard and replace it in the affected service. Do not keep using a leaked key while investigating.

## Diagnose access failures

* **401 Unauthorized:** the key may be invalid, revoked, missing, or for the wrong environment. Check both the key and API host.
* **403 Forbidden:** check the permissions granted to the key and any operation-specific authorization requirements.

If you cannot manage API keys, ask your organization's dashboard administrator for access.
