> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agents.labs.bandwidth.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate with Labs credentials and the correct workspace permissions.

Sign in through Labs Auth to initialize your workspace before using the API. Your credentials identify a user; that user's membership and role determine access to workspace resources.

## Labs API keys

Create and revoke user API keys through the Labs platform. Copy a new key when shown and keep it in your application's secret store. Key management is not available inside the Agent Builder console in this release.

Set `LABS_AUTH_API_KEY` to your key and `VOAI_ORGANIZATION_ID` to the positive integer ID of a workspace you belong to. Ask your workspace administrator for the ID if needed.

```bash theme={null}
curl --fail-with-body 'https://agents.labs.bandwidth.com/api/v1/workflow/fetch' \
  -H "X-BW-LABS-AGENTS-API-KEY: ${LABS_AUTH_API_KEY}" \
  -H "X-VOAI-ORGANIZATION-ID: ${VOAI_ORGANIZATION_ID}"
```

Both headers are required for API-key requests. The workspace ID is checked against the key owner's membership; changing your workspace in the console does not change an API request's workspace. Keys inherit their owner's permissions and do not grant administrator access by themselves.

## OAuth user access tokens

Endpoints that support user access tokens accept:

```bash theme={null}
curl --fail-with-body 'https://agents.labs.bandwidth.com/api/v1/workflow/fetch' \
  -H "Authorization: Bearer ${LABS_ACCESS_TOKEN}"
```

Obtain a user access token through an authorized Labs OAuth client. Contact your Labs administrator if your application does not have one. User tokens expire within 15 minutes; your OAuth client must obtain a fresh token when needed. Keep tokens on your server and out of browser storage and logs.

Bearer requests use the user's selected workspace. Outbound call and campaign endpoints require a user access token with the Labs `super_user` role. Starting calls or changing campaigns also requires Editor or higher workspace access. Configuring telephony requires Admin or Owner access plus `super_user`.

API keys cannot call these bearer-only endpoints. The endpoint reference shows which credential types each operation accepts. Do not send both a bearer token and an API key in one request, and do not use an API key as a bearer token. The former `X-API-Key` header is not supported.

## Rotate or revoke a key

Create a replacement through Labs, update your application's secret, and verify a read request before revoking the old key. Revocation takes effect on the next API request. Removing a user's workspace membership also removes that user's API-key access to that workspace.

The interactive API reference sends requests to the configured API host. Write requests change workspace data, and outbound call requests can place real calls.

See [roles and permissions](/core-concepts/roles-and-permissions) and [errors](/api-reference/errors) when a valid credential cannot perform an operation.
