> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lupin.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Bearer keys, scoped keys and the 40-permission gate.

# Authentication

```bash theme={null}
curl $BASE/v0/auth/me -H "authorization: Bearer $KEY"
# → {"organization_id":"org_…","api_key_id":"key_…","permissions":{…}}
```

## Key scopes

Keys are created with optional scope:

* Org key (default) — sees everything in the org, minus permission gates.
* `POST /v0/projects/:project_id/api-keys` — project-scoped.
* `POST /v0/emails/inboxes/:inbox_id/api-keys` — inbox-scoped.

Scoped keys 404 on anything outside their scope. Delete a key with
`DELETE /v0/api-keys/:api_key_id` (or the scoped equivalents).

## Permissions

`POST /v0/api-keys` accepts `{ "name": "…", "permissions": { "message_send": false } }`.
Every permission defaults to allow; set one to `false` to deny. Gates include
`inbox_*`, `message_*`, `draft_*`, `webhook_*`, `domain_*`, `list_*`,
`label_spam_read`, `label_blocked_read`, `label_unauthenticated_read`,
`label_trash_read`, `metric_read`, `event_read`, `pod_*`, `api_key_*`, `org_read`.

Denied reads on gated labels behave as 404 (nothing leaks); denied writes are
403 `missing_permission`.
