> ## Documentation Index
> Fetch the complete documentation index at: https://developers.redo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> How to authenticate v3 GraphQL requests

The v3 data endpoint is authenticated with a **bearer token** that is scoped to
a single store.

## Getting your credentials

### API token

To create an API token:

1. Log in to your [Redo Dashboard](https://app.getredo.com)
2. Go to **Settings** → **Developer**
3. In **API tokens**, click **Create token**, then name it and choose its scopes
4. Copy the token from the confirmation dialog. It starts with `redo_sk_`.

<Warning>
  Store your API token securely. It is only shown once, when created.
</Warning>

### Store ID

Your Store ID is part of the data endpoint path. It is shown in the **General**
section of **Settings** → **Developer** in the Redo Dashboard.

## Making authenticated requests

Send every operation as a `POST` to the data endpoint for your store, with the
token in the `Authorization` header:

```http theme={null}
POST /v3/account/{storeId}/graphql HTTP/1.1
Host: api.getredo.com
Authorization: Bearer redo_sk_...
Content-Type: application/json

{"query":"{ products(first: 10) { nodes { id title } } }"}
```

The token is checked against the store in the path. A malformed header, an
unknown token, and a token that belongs to a different store all fail the same
way, with HTTP `401` and an `Unauthorized` error, so they cannot be told apart:

```json theme={null}
{ "errors": [{ "message": "Unauthorized" }] }
```

<Warning>
  Never share your API token publicly or commit it to version control.
</Warning>

## Scopes

Tokens carry **scopes** that determine which fields they may read or write.
Because a nested field's scope adds to its parent's, a request needs the union
of every scope along its selection paths. A request that selects any field its
token is not scoped for is rejected before it runs, with HTTP `403` and the
error code `INSUFFICIENT_SCOPE`.

Choose a token's scopes in **Settings** → **Developer** when you create it, and
grant only the scopes it needs. See
[Access scopes](/docs/api-reference/v3/reference/scopes) for the full list, and
the **Required scopes** on each query, mutation, and field in the reference.

## Introspection without a token

The [schema endpoint](/docs/api-reference/v3/introduction#introspection)
(`https://api.getredo.com/v3/graphql-schema`) is unauthenticated and exposes the
schema only, never store data. Use it to explore types and generate clients
without a token.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.