> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Internal links on these pages omit the .md extension. Append .md to a docs page URL, or send an Accept: text/markdown header, to get that page as markdown.

# Authentication

> How to authenticate with the Base44 Workspace API

All Workspace API requests authenticate with a personal access token. Include it as a Bearer token in the `Authorization` header with every request:

```bash theme={null}
Authorization: Bearer YOUR_PERSONAL_ACCESS_TOKEN
```

<Note>
  **What the token needs:**

  * It has to belong to the workspace you're calling for. A token for another workspace is refused.
  * It needs **Full access**. A **Read-only** token is refused, even on the endpoints that only read.
  * Workspace API keys aren't accepted.
</Note>

A personal access token acts as you, so a request only succeeds if your own workspace role allows the action. Changing invitations and groups needs the owner or admin role. Listing groups and their members also works for editors.

## Get an access token

**To create a personal access token:**

1. In your workspace, click your workspace name at the bottom left, then click **Settings**.
2. Click **Secrets** in the sidebar.
3. Click the **Personal access tokens** tab.
4. Click **Create access token**.
5. Enter a **Name**, and under **Permission**, choose **Full access**.
6. Click **Create access token**, then copy the value.

See [Creating an access token](/Workspaces/Personal-access-tokens#creating-an-access-token) for every option.

<Warning>
  Your personal access token acts as your Base44 account. Treat it like a password, don't share it, and don't commit it to version control.
</Warning>

## Example request

```curl theme={null}
curl --request GET \
  --url 'https://app.base44.com/api/workspace/groups?workspaceId=67e0b12c4d8a3f005b21c9e4' \
  --header 'Authorization: Bearer YOUR_PERSONAL_ACCESS_TOKEN'
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.