# The API key was not accepted

> 401 authentication_failed

The key is missing, mistyped, unknown, revoked or expired. Every one of those gets this same answer, so an error never tells a stranger which keys are real.

## What to do

Send `Authorization: Bearer <key>` with a key from the console's API keys page. A rotated key's old secret stops working when its overlap ends.

## Retrying

No: the same request gets the same answer until something is changed.
