# Authentication

Most SpaceKeep API endpoints require authentication. This page explains how to authenticate your requests.

## How authentication works

SpaceKeep uses token-based authentication. When you sign up or log in, SpaceKeep issues a token that you include in subsequent API requests.

## Getting a token

You can obtain a token by:

- **Signing up** — `POST /auth/signup`
- **Logging in** — `POST /auth/login`
- **Using an OAuth provider** — GitHub, Google, or Discord
- **Using a passkey** — WebAuthn authentication

## Using your token

Include your token in your API requests. The token is sent as a cookie named `access_token`.

## Token expiry

Tokens expire after 7 days. When a token expires, you will need to authenticate again to get a new token.

## Related

- [API Overview](/developers/) — API basics
- [API Reference](/developers/api-reference/) — endpoint documentation
