# Authentication

To access the API, you must authenticate requests using an API key. Support for OAuth 2.0 is coming soon.

## Getting an API key

1. Go to your [Profile page](https://account.databox.com/profile) (`Account Management > Profile`).
2. In the **Password & Security** section, find the **API key** option.
3. Click **Create** to generate a new key.


Permissions Required
Access to API key management is currently limited to **Admin** users.

### Restricting access by IP

You can optionally restrict usage of your API key to specific IP addresses:

1. Click **Manage allowed IPs**.
2. Enter one or more IP addresses, pressing **Enter** after each.
3. When finished, click **Save**.


Only requests coming from the specified IPs will be accepted.

## Key ownership and permissions

- API keys are **user-specific**.
- Each key inherits the access rights and permissions of the user who created it.


## Acting on an account

By default, a request runs against the organization tied to the API key that authenticated it. If that organization has [accounts](/docs/api/glossary#account) enabled, you can instead act on one of them by passing the account's ID in the `x-account-id` header:

```
x-account-id: 4754489
```

Omit the header to act on the main organization, same as before.

Most endpoints that read or modify organization-specific data accept `x-account-id` — data sources, datasets, metrics, users, connections, Databoards, and the organization resource itself. It has no effect on endpoints that aren't scoped to a specific organization, such as static reference lists (available countries, time zones, integrations), the `Accounts` resource itself (managing the organization's own roster of accounts happens on the main organization), your own profile, and key validation. See each operation's parameters in the [API Reference](/docs/api/api.databox.com) to confirm whether it's supported.

Billing is self-managed-accounts only
`x-account-id` only returns billing details for a **self-managed** account — an account that handles its own usage and billing independently of its organization. Managed accounts don't have independent billing, so their billing endpoints resolve to the organization regardless of this header.

## Validating an API key

You can validate an API key using the following endpoint:

```shell curl
curl -i -X GET \
  https://api.databox.com/v2/auth/validate-key \
  -H 'x-api-key: YOUR_API_KEY_HERE'
```