> ## Documentation Index
> Fetch the complete documentation index at: https://silmaril.dev/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate Firewall API requests with your deployment API key.

Send your provisioned API key in the `x-api-key` header and JSON in the request body.

```bash theme={"theme":"github-light-default"}
curl --request POST "$SILMARIL_API_URL" \
  --header "x-api-key: $SILMARIL_API_KEY" \
  --header "Content-Type: application/json" \
  --data '{"text":"Summarize this release note.","hook":"user_input"}'
```

`SILMARIL_API_URL` is your complete classify URL. It already includes `/classify` and any deployment path prefix. Get both environment values through [deployment access](/docs/start/quickstart#get-access).

## Keep the key in your service

Make API calls from the service that owns model inference, tool execution, or orchestration. Store the key in that service's environment or secret manager. Keep it out of browser bundles and source control.

## Authentication errors

A `403` response indicates that the request is not authorized. Check that the key belongs to the deployment you are calling. Error bodies can differ between hosted gateways and self-hosted runtimes; they do not contain a classification verdict.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.