> ## Documentation Index
> Fetch the complete documentation index at: https://developers.fastdrop.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> How to authenticate with the FastDrop API

All API requests (except `/v1/capabilities`) require an API key passed in the `X-API-Key` header.

## Getting an API key

<Steps>
  <Step title="Sign up">
    Go to [fastdrop.io/developers](https://fastdrop.io/developers) and enter your email.
  </Step>

  <Step title="Verify your email">
    Click the verification link sent to your inbox (expires in 24 hours).
  </Step>

  <Step title="Save your key">
    Your API key is shown once after verification. It looks like `fd_live_aBcDeFgH...`. Store it securely — it cannot be retrieved later.
  </Step>
</Steps>

The free tier gives you **100 credits/month** with no credit card required. Upgrade anytime at [fastdrop.io/developers](https://fastdrop.io/developers).

## Using your API key

Pass your key in the `X-API-Key` header on every request:

```bash theme={null}
curl https://api.fastdrop.io/api/v1/usage \
  -H "X-API-Key: fd_live_your_key_here"
```

<Warning>
  Never expose your API key in client-side code, public repositories, or browser requests. Always call the FastDrop API from your backend server.
</Warning>

## Key rotation

If your key is compromised, rotate it immediately:

```bash theme={null}
curl -X POST https://api.fastdrop.io/api/v1/keys/rotate \
  -H "X-API-Key: fd_live_your_current_key"
```

The old key is invalidated immediately. If you have an email on file, the new key is sent to your inbox. Otherwise, it's returned in the response body (shown once).

## Rate limits

Each plan has a per-minute request limit:

| Plan | Requests/min | Concurrent jobs |
| - | - | - |
| Free | 10 | 3 |
| Starter | 20 | 5 |
| Growth | 40 | 15 |
| Scale | 80 | 50 |

## Video limits

| Limit | Value |
| - | - |
| Maximum duration | 60 minutes |
| Maximum file size | 500 MB (Free), 1 GB (Starter), 2 GB (Growth), 5 GB (Scale) |

A video over the duration limit fails during processing and its credits are
returned automatically. Send `duration_seconds` with the request to be declined
up front instead, before anything is charged.

When you exceed the rate limit, you'll receive a `429` response:

```json theme={null}
{
  "error": {
    "code": "rate_limited",
    "message": "Rate limit exceeded",
    "details": {
      "retry_after_seconds": 12
    }
  }
}
```

Wait for the number of seconds in `retry_after_seconds` before retrying.

## Error responses

All authentication errors follow a consistent format:

### Missing or invalid key

```json 401 theme={null}
{
  "error": {
    "code": "invalid_api_key",
    "message": "Missing or invalid API key"
  }
}
```

### Insufficient credits

```json 402 theme={null}
{
  "error": {
    "code": "insufficient_credits",
    "message": "Not enough credits for this request",
    "details": {
      "credits_required": 4,
      "credits_available": 2
    }
  }
}
```

### Rate limited

```json 429 theme={null}
{
  "error": {
    "code": "rate_limited",
    "message": "Rate limit exceeded",
    "details": {
      "retry_after_seconds": 12
    }
  }
}
```

## Response headers

All API v1 responses include:

| Header | Description |
| - | - |
| `X-API-Version` | API version (`1.0`) |
| `Retry-After` | Seconds until rate limit resets (only on 429) |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.