> ## Documentation Index
> Fetch the complete documentation index at: https://docs.daily.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> How to authenticate with the Daily REST API.

The Daily REST API uses API keys to authenticate requests. Your API key is available in the **Developers** section of the Daily [dashboard](https://dashboard.daily.co/).

* **Domain owners** can view and regenerate the API key.
* **Members** do not have access to the API key. Request it from an owner, or ask an owner to grant you administrator privileges.

<Note>
  **Using Daily through Pipecat Cloud?** You have a separate, integrated Daily API key that comes with your Pipecat Cloud account. Find it under **Settings → Daily (WebRTC)** in the [Pipecat Cloud dashboard](https://pipecat.daily.co/). It has the same capabilities as a key from `dashboard.daily.co`, and 1:1 voice minutes are free when your agent runs on Pipecat Cloud. The two keys belong to different accounts, so a recording or session created with one key won't show up when you query with the other. See the [Daily WebRTC guide](https://docs.pipecat.ai/pipecat-cloud/guides/daily-webrtc) for details.
</Note>

## Staging and testing

Daily doesn't support adding a second domain to an existing account. To set up a staging environment, sign up for a separate Daily account using a variant of your domain name (e.g. `yourdomain-dev`). The new account's API key is immediately available under the **Developers** tab in the dashboard.

## Making authenticated requests

Include your API key in the `Authorization` header of every request:

```bash theme={null}
curl --request GET \
  --url https://api.daily.co/v1/rooms \
  --header 'Authorization: Bearer DAILY_API_KEY'
```

Each API key is scoped to a single Daily domain.

<Warning>
  Never include your API key in client-side browser code. Treat it like a password.
</Warning>

HTTPS is required for all Daily REST API requests.

## Authentication errors

| Condition | HTTP status | `error` value |
| - | - | - |
| `Authorization` header missing or malformed | `400` | `authorization-header-error` |
| API key is not valid | `401` | `authentication-error` |

## Rate limits

Daily rate-limits the API to ensure stability for all users. If you exceed the limits, you'll receive a `429` response with `error: "rate-limit-error"`. Limits are counted per API key, per endpoint.

| Endpoints | Limit |
| - | - |
| Most endpoints, including `POST /rooms`, `DELETE /rooms/:name`, `GET /rooms`, presence, and webhooks | 20 req/sec, or 100 req per 5-second window |
| Analytics and data endpoints, including `GET /meetings`, `GET /recordings`, `GET /usage`, API and webhook logs, transcripts, the batch processor, phone numbers, verified caller IDs, SIP trunks, and domain dial-in config | \~2 req/sec, or 50 req per 30-second window |
| Start dial-out, start dial-in, and start live streaming (these three share one budget) | \~1 req/sec, or 5 req per 5-second window |
| Start recording (its own separate budget) | \~1 req/sec, or 5 req per 5-second window |
| Batch room create and delete (`POST /batch/rooms`, `DELETE /batch/rooms`) | 10 req per 30-second window |

Starting dial-out, starting dial-in, and starting a live stream all pull from the same budget. If you start a dial-out and a live stream back to back with the same API key, both count against that one budget.

Starting a recording is counted on its own. A recording start does not use up any of the budget shared by dial-out, dial-in, and live streaming.

Handle `429` responses by retrying with [exponential backoff](https://en.wikipedia.org/wiki/Exponential_backoff). [Contact support](https://www.daily.co/contact/support) if you need higher limits.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.