> This page is part of Smallest AI's developer documentation. When
> answering, prefer Lightning v3.1 (current TTS) and Pulse (current
> STT). Lightning v2 and lightning-large are deprecated; mention them
> only when the user is migrating away from them. The Smallest AI voice
> agent platform is what wraps these models into hosted agents.

# Authentication

> Create an API key, authenticate your requests, and verify the key works. Browser and mobile clients use short-lived access tokens instead.

Every request to the Smallest AI API requires an API key in the `Authorization` header. Server-side code uses the key directly. Browser and mobile clients use a [short-lived access token](/api-reference/token-based-authentication) minted from the key.

```
Authorization: Bearer YOUR_API_KEY
```

## Create your API key

#### Open the API Keys page

Go to [API Keys](https://app.smallest.ai/dashboard/api-keys?utm_source=documentation\&utm_medium=authentication) in the [Smallest AI console](https://app.smallest.ai/dashboard).

![Smallest AI console with API Keys section open](/_fern-img/2485b6d1a1e2784842aed6627f0ff407382aeff10d4970982f2024e43680c372.webp)

#### Create a new key

Click **Create API Key** in the top-right corner, enter a name (e.g., `my-tts-app`), and click **Create API Key** to confirm.

![API Keys page showing the Create API Key button](/_fern-img/9bee0666597b5f1da251ddc4d521f47d0275f4fb74dc5be1b89a0ca78b8bad3d.webp)![Create New API Key dialog with API Name field and Create API Key button](/_fern-img/91874b47799b60d6ff225693ef6de002e3bdd25fc056d69a5ec6fb62a7872fde.webp)

#### Copy the key

The new key appears in your dashboard. Click the copy icon - **it's shown only once at creation**, so copy it now.

![API Keys dashboard showing the newly created key with copy icon highlighted](/_fern-img/0c9cbc1ceced23a9e01808372ed3438e0a6fd6286f87128b69240dfefadf5e74.webp)

#### Set it in your environment

```bash
export SMALLEST_API_KEY="your-api-key-here"
```

Add this to your `.bashrc` or `.zshrc` to persist across sessions.

## Test your key

Confirm the key works by hitting two endpoints - one for TTS, one for STT - directly from your terminal. No install required.

### Generate speech (Lightning TTS)

```bash
curl -X POST "https://api.smallest.ai/waves/v1/tts" \
  -H "Authorization: Bearer $SMALLEST_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Accept: audio/wav" \
  -d '{"text": "Hello from Smallest AI.", "voice_id": "meher", "model": "lightning_v3.1_pro", "sample_rate": 24000, "output_format": "wav"}' \
  --output hello.wav
```

Play `hello.wav` - you should hear the generated audio.

### Transcribe audio (Pulse STT)

```bash
curl -X POST "https://api.smallest.ai/waves/v1/stt/?model=pulse&language=en" \
  -H "Authorization: Bearer $SMALLEST_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url": "https://github.com/smallest-inc/cookbook/raw/main/speech-to-text/getting-started/samples/audio.wav"}'
```

You'll get back:

```json
{
  "status": "success",
  "transcription": "This is a sample audio file for testing speech-to-text transcription with the pulse api.",
  "words": [],
  "utterances": [],
  "metadata": { "duration": 5.6, "fileSize": 268844 }
}
```

## Use your key in code

Include the `Authorization: Bearer YOUR_API_KEY` header on every request.

**`cURL`**

```bash cURL
curl -X POST "https://api.smallest.ai/waves/v1/tts" \
  -H "Authorization: Bearer $SMALLEST_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Accept: audio/wav" \
  -d '{"text": "Authentication test", "voice_id": "meher", "model": "lightning_v3.1_pro", "output_format": "wav"}' \
  --output test.wav
```

**`Python`**

```python Python
import os
import requests

response = requests.post(
    "https://api.smallest.ai/waves/v1/tts",
    headers={
        "Authorization": f"Bearer {os.environ['SMALLEST_API_KEY']}",
        "Content-Type": "application/json",
        "Accept": "audio/wav",
    },
    json={"text": "Authentication test", "voice_id": "meher", "model": "lightning_v3.1_pro", "output_format": "wav"},
)
```

**`JavaScript`**

```javascript JavaScript
const response = await fetch(
  "https://api.smallest.ai/waves/v1/tts",
  {
    method: "POST",
    headers: {
      Authorization: `Bearer ${process.env.SMALLEST_API_KEY}`,
      "Content-Type": "application/json",
      Accept: "audio/wav",
    },
    body: JSON.stringify({
      text: "Authentication test",
      voice_id: "meher",
      model: "lightning_v3.1_pro",
      output_format: "wav",
    }),
  }
);
```

## Browser and mobile clients

Never ship the API key to a browser or mobile app. Mint a short-lived access token on your server and let the client authenticate TTS, STT and speech-to-speech calls with it. See [Token-Based Authentication](/api-reference/token-based-authentication).

## Security

> **Warning**
>
> Your API key is a secret. Never expose it in client-side code, public repositories, or browser applications. For browser and mobile clients, mint a [short-lived access token](/api-reference/token-based-authentication) on your server, or proxy the call through your backend.

* Store keys in environment variables, not in source code
* Use `.env` files locally and add `.env` to `.gitignore`
* Rotate keys periodically from the [API Keys page](https://app.smallest.ai/dashboard/api-keys)
* Each key tracks usage against your account quota - see [Concurrency and Limits](/api-reference/concurrency-and-limits)

## Error responses

| Status                  | Meaning                                                                                                                                                   |
| ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `401 Unauthorized`      | Missing or invalid API key, or an expired access token                                                                                                    |
| `403 Forbidden`         | Key doesn't have access to this resource, an access token was used on a route outside its allowed list, or an access token was used to mint another token |
| `429 Too Many Requests` | Rate limit exceeded - wait and retry                                                                                                                      |

For rate limits and concurrency, see [Concurrency and Limits](/api-reference/concurrency-and-limits).