# Authentication Personal keys, scopes, and account access. ## Bearer authentication Send your personal key on every generation API request: ```http Authorization: Bearer lgk_… ``` The `lgk_` secret contains 64 lowercase hexadecimal characters. Session cookies are not a substitute for bearer authentication on the public API. Never send a key in a query string. ## Scopes | Scope | Access | | --- | --- | | `read` | List models and voices; read owned public API tasks. | | `generate` | Submit media, text, or video analysis; upload reference media or voices. | A generate-only key cannot poll tasks or list models. Use both scopes for a complete generation workflow. Use read-only access for discovery and monitoring. ## Manage keys Create and revoke keys through **Settings → API keys** in the signed-in Lets Gen app. You can name a key, set a future UTC expiration, and set a calendar-month Gem cap. There is a limit of 50 non-revoked keys. Secret values are shown only once; the platform stores hashes, not plaintext keys. Key management endpoints use signed-in account authentication, not personal keys, and are separate from the generation API. Revocation or expiration stops further access, including saved text-response replay. Revoking a key does not erase billing evidence or cancel existing provider work. You can also manage these same personal keys on [WeGen](https://wegen.art/developer/api-keys), using its standalone **API keys** page in the workspace or account menu. ## Account policies Your account's Gem balance, LLM allowance, paid-Gem consent, content preference, network/account blocks, and regional restrictions continue to apply. An API key does not bypass moderation or publish private content. `401 INVALID_API_KEY` means the key is missing, malformed, revoked, or expired. `403 INSUFFICIENT_SCOPE` means the key lacks the required scope. See [Errors](/docs/api/errors) for other failures.