# Authentication

> How to authenticate with the ChargeNow API using a Bearer token issued by the ChargeNow team.

## Getting credentials

Tokens are issued by the ChargeNow team. To get started, contact us with your organisation name and a brief description of what you're building. We'll create an integration and issue your first token.

For sandbox access, see the [Sandbox](/docs/charge-now/guides/sandbox) guide.

## Making authenticated requests

Include your token as a Bearer token in the `Authorization` header of every request. All requests without a valid token are rejected.

## Token lifecycle

Tokens have a long validity period and are also active until explicitly revoked. We'll tell you the exact expiry when we issue your token.

To rotate or revoke a token, contact us. We recommend rotating tokens periodically and immediately if you suspect a token has been compromised.

**Keep your token secret.** Do not commit it to source control or expose it in client-side code.

## Authentication errors

If a request fails due to authentication, you will receive a `401` response. The most common causes are a missing token, an expired token, or a token that has been revoked. See the [Errors](/docs/charge-now/guides/errors) guide for how to handle these.
