> Fetch clean Markdown by appending `.md` to any page URL under https://signalwire.com/docs or requesting it with the HTTP header `Accept: text/markdown`. The root index at https://signalwire.com/docs/llms.txt lists the available documentation indexes. # API credentials > Learn how to access your SignalWire API Space. The API credentials found on this page are your key to accessing SignalWire's APIs and SDKs. Open **API Credentials** in the Dashboard to find the current Project's **Project ID** and **Space URL**. Reveal and copy an existing API token or select **+ New** to create one. Most SignalWire API endpoints require authentication using [HTTP Basic Auth](https://en.wikipedia.org/wiki/Basic_access_authentication). HTTP Basic Authentication requires you to send an Authorization header with your Project ID and API Token. Each Project has its own Project ID and API Authentication Tokens you will need to use when making a request to the API. Some methods will also require you to pass your Space URL. [Subprojects](/docs/platform/projects#subprojects) work the same way: each one has its own Project ID and tokens, and a root Project can issue a token for one of its Subprojects with [Create API token](/docs/apis/rest/project-tokens/create-token). * **Project ID:** Use this UUID to specify your Project to the API. * **Space URL:** Use this URL to access SignalWire APIs. For example: `https://{Your_Space_Name}.signalwire.com/api/calling/calls` * **API Tokens:** Authentication tokens to access the API. You can have multiple tokens for each Project. An API token acts for one Project. To administer the Space itself over the API, such as managing members, the balance, or billing, or to create a root Project, use a [Personal access token](/docs/apis/authorization#personal-access-tokens) instead. It is created from your user menu in the Dashboard rather than on this page, and it carries your owner or admin role instead of a Project's scopes. > **Info** > > API tokens are protected and used server-side to access the API. > The tokens we refer to when using Video, Chat, or Fabric products in the browser are not the same tokens we generate and store here. > Instead, you use your API token to call an endpoint that generates a client-side token: > > * **Video Room Tokens**: Generated via the > [Create Room Token](/docs/apis/rest/video/room-tokens/create-room-token) endpoint. > * **Chat Tokens**: Generated for chat applications via the > [Create Chat Token](/docs/apis/rest/chat-tokens/create-chat-token) endpoint. > * **[Subscriber](/docs/platform/subscribers) Access Tokens (SAT)**: Generated via the > [Create Subscriber Token](/docs/apis/rest/subscribers/tokens/create-subscriber-token) endpoint for Fabric applications. > > For more details on authentication methods, see the [REST API Authorization guide](/docs/apis/authorization). ## Generate a new API token To generate a new API token, click the blue "+ New" button. A "New API Token" form will open. Give your token a descriptive name to help differentiate it in logs and for debugging. You can edit the token name and allowed scopes later by clicking the **⋯** button and selecting "Edit." You may also delete a token from the same dropdown menu or the Edit page. ### Token format New API tokens begin with `swapi_` and are 42 characters long. Tokens created earlier begin with `PT` and are 50 characters long. Both formats authenticate the same way, and a Project can hold tokens in both formats at the same time. Existing `PT` tokens are not deprecated and have no end date, so there is nothing to migrate. Treat a token as an opaque string. Don't parse it, match it against a pattern, or assume a fixed length, in either format. ### Token scopes API tokens can be configured with specific scopes that limit which APIs the token can access. When creating or editing an API token in the Dashboard, you can select which scopes to enable under the "Permissions" section. > **Tip** > > For security best practices, only enable the scopes your application actually needs. This limits the potential impact if a token is compromised. If your API request returns a `401 Unauthorized` error, verify that your API token has the required scope enabled for that endpoint in the Dashboard. ## Use an API token All API requests must be made with proper authentication over HTTPS. Calls made over plain HTTP or without auth will fail. Find the correct credentials structure for each specific call in the [SDK Reference](/docs/server-sdks/reference), [REST API Reference](/docs/apis), or in a specific [Guide](/docs/browser-sdk/guides/overview) you may wish to follow. For a general example, we can look at how to list video rooms with the **REST API**: #### cURL This example uses curl with the `-u` flag to make a request with Basic Auth. ```shell curl https://.signalwire.com/api/video/rooms \ -u ':' ``` #### Node.js We use the external dependency [Axios](https://axios-http.com/) to make this call, so it must also be imported and installed. ```javascript // npm install axios import axios from "axios"; await axios .get("https://.signalwire.com/api/video/rooms", { auth: { username: "", password: "" }, }) .then((response) => { console.log(JSON.stringify(response.data)); }) .catch((error) => { console.log(error); }); ``` Or with the **Realtime SDK**, you may use these credentials to create a Video Client. ```javascript import { Video } from "@signalwire/realtime-api"; const video = new Video.Client({ project: "", token: "", }); ``` Note that you are not required to pass the Space URL when working with the SDK. > Learn how to access your SignalWire API Space.