> Fetch clean Markdown by appending `.md` to any page URL under https://signalwire.com/docs or requesting it with the HTTP header `Accept: text/markdown`. The root index at https://signalwire.com/docs/llms.txt lists the available documentation indexes. # Authorization SignalWire REST APIs support two authentication methods: **Basic Authentication** and **Bearer Authentication**. Each endpoint specifies which method it accepts. ## Basic authentication [Basic Authentication](https://swagger.io/docs/specification/v3_0/authentication/basic-authentication/) is the standard method for authenticating with SignalWire REST APIs, using your **Project ID** and **API Token**. ### How it works Include an `Authorization` header with each request: ``` Authorization: Basic ``` To build the `credentials` string: 1. Join your Project ID and API Token with a colon: `ProjectID:APIToken` 2. [Base64](https://developer.mozilla.org/en-US/docs/Glossary/Base64) encode the result #### Example Given the Project ID `a1b2c3d4-e5f6-7890-abcd-ef1234567890` and API Token `swapi_0123456789ab0123456789ab0123456789ab`: ```bash # In the format username:password a1b2c3d4-e5f6-7890-abcd-ef1234567890:swapi_0123456789ab0123456789ab0123456789ab # Base64 encoded: YTFiMmMzZDQtZTVmNi03ODkwLWFiY2QtZWYxMjM0NTY3ODkwOnN3YXBpXzAxMjM0NTY3ODlhYjAxMjM0NTY3ODlhYjAxMjM0NTY3ODlhYg== # Full header: Authorization: Basic YTFiMmMzZDQtZTVmNi03ODkwLWFiY2QtZWYxMjM0NTY3ODkwOnN3YXBpXzAxMjM0NTY3ODlhYjAxMjM0NTY3ODlhYjAxMjM0NTY3ODlhYg== ``` API tokens created earlier begin with `PT` and are 50 characters long. Both formats authenticate the same way, so treat a token as an opaque string rather than matching it against a pattern. See [API credentials](/docs/platform/your-signalwire-api-space) for details on token format. ### Finding your credentials Your Project ID and API Tokens are available in the [SignalWire Dashboard](/docs/platform/your-signalwire-api-space). In the Dashboard, open **API Credentials**. Copy the **Project ID**, then reveal and copy an existing API token or select **+ New** to create one. ### API token scopes Tokens can be scoped to limit API access. Select scopes when creating or editing a token in the Dashboard. Getting a `401 Unauthorized`? Check that your token has the required scope. Manage scopes in the [SignalWire Dashboard](/docs/platform/your-signalwire-api-space). ### cURL examples **`cURL`** ```bash title="cURL" # With base64-encoded credentials curl https://{Your_Space_Name}.signalwire.com/api/laml/2010-04-01/Accounts/{YourProjectId}/Calls \ -H 'Authorization: Basic YTFiMmMzZDQtZTVmNi03ODkwLWFiY2QtZWYxMjM0NTY3ODkwOnN3YXBpXzAxMjM0NTY3ODlhYjAxMjM0NTY3ODlhYjAxMjM0NTY3ODlhYg==' # Encoded inline using the Bash pipe operator curl https://{Your_Space_Name}.signalwire.com/api/laml/2010-04-01/Accounts/{YourProjectId}/Calls \ -H "Authorization: Basic $(echo -n "YourProjectId:YourApiToken" | base64)" # Encoded inline with cURL's -u flag curl https://{Your_Space_Name}.signalwire.com/api/laml/2010-04-01/Accounts/{YourProjectId}/Calls \ -u YourProjectId:YourApiToken ``` --- ## Security best practices 1. **Keep API credentials server-side.** Use Bearer tokens for client applications. 2. **Set short token lifetimes** to reduce risk if a token leaks. 3. **Scope tokens narrowly**—only grant what's needed. 4. **Always use HTTPS.** Plain HTTP requests will fail. 5. **Rotate API tokens periodically** from your Dashboard.