> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nadcab.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate every request with a bearer API key.

Every request must include your API key in the `Authorization` header:

```http theme={null}
Authorization: Bearer ncl_your_api_key
```

## Create a key

1. Sign in to the [Nadcab Labs Console](https://cc.nadcab.com).
2. Open **Settings → Key & Access**.
3. Create a key and copy it. It is shown in full only once.

<Warning>
  Your API key can move funds and create cards. Keep it on your server, never in browser or mobile app code, and rotate it immediately if it leaks.
</Warning>

## Example

```bash theme={null}
curl https://cc.nadcab.com/api/v1/account/balance \
  -H "Authorization: Bearer $NADCAB_API_KEY"
```

## Restrict access by IP

Limit API access to your servers with [Set IP allowlist](/api-reference/api-settings/set-ip-allowlist). Requests from other IP addresses are rejected once an allowlist is set.

## Protect card data

Full card numbers and CVVs are returned encrypted with your RSA public key. See [Card data encryption](/guides/card-data-encryption).
