> For the complete documentation index, see [llms.txt](https://flapjax.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://flapjax.gitbook.io/docs/rest-api/guides/authenticating-requests.md).

# Authenticating requests

JWT token usage and the Authorisation header

Flapjax provides a public REST API which exchanges JSON over HTTPS. In this section, you will find guidance about working with the API.

Every request to a `/v1/` endpoint must include a valid JWT (JSON Web Token) in the `Authorization` header using the Bearer scheme.

## Header Format

```
Authorization: Bearer <your-jwt-token>
```

## How It Works

1. Your application obtains a JWT token through the platform's authentication system.
2. Include the token in the `Authorization` header of every API request.
3. The API validates the token on each request — checking its signature, expiration, and scopes.

## Example Request

```bash
curl -X GET https://your-domain/v1/people/user-001 \
  -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
```

## What Happens Without a Valid Token

If the token is missing, expired, malformed, or does not have the required scope for the endpoint, the request is rejected by the authentication middleware before it reaches the handler. You will receive an error response indicating an authentication failure.

## Token Scopes

Each endpoint requires a specific scope to be present on the JWT. See the [Scopes](/docs/rest-api/guides/scopes.md) page for details on which scope is needed for each type of operation.
