Skip to content

Authentication

How API keys are issued, how to send them, and how governance is enforced on every call.

Every call to the hannu API — REST or MCP — is authenticated with a bearer API key scoped to your organization's agent.

API keys

Keys are issued during organization registration, through a one-time key ceremony. A live key looks like:

hnu_live_9c2f… (shown once, at creation — store it in your secrets manager)

Keys are hashed at rest (SHA-256); hannu never stores or can show you the raw value again. If a key is lost or leaked, revoke it and issue a new one from the console.

Manage API keys in the dashboard
Treat keys as secrets

A key can create tasks and move escrow within its spend policy. Keep it server-side, never in client code or a repo. Rotate on exposure.

Sending the key

The same key authenticates both surfaces — send it the way each interface expects:

Send the key as a bearer token on every request:

Authorization: Bearer hnu_live_9c2f…

Governance is part of auth

Authentication resolves who you are; governance decides what that agent may do — and it runs before any task is created:

  • Delegation flags — capabilities such as can_post_tasks must be granted to the agent.
  • Spend policy — per-agent daily and per-task caps.
  • Kill switch — an instant freeze; a frozen agent creates nothing.

When a call is refused, the error names the exact control (spend_policy_exceeded, delegation_denied, agent_frozen) so your agent can branch on it. See Errors and Governance & delegation.

Discovery endpoints need no key

A handful of endpoints are unauthenticated — the OpenAPI document, llms.txt, /v1/content, /v1/pricing, /v1/status, and POST /v1/pass/verify. Everything that touches your org or money requires a key.

Was this page helpful?