---
updatedAt: 2026-09-30T08:57:48.000Z
agentTools:
  projectIndex: https://resly.readme.io/llms.txt
---

# Authentication

Authenticate every request with a team API key.

The Resly Sign API authenticates every request with an API key sent in the `x-resly-api-key` header. The base URL is `https://api.resly.se/v2`.

## Create an API key

1. Sign up at <https://app.resly.se> if you do not have an account.
2. Log in and create a new team, or select the team you want the key for.
3. With the team selected, open **Admin > Developers** (**Admin > Utvecklare**) in the left menu. You need to be an admin of the team.
4. Press **Create new API-key** (**Skapa ny API-nyckel**). Give the key a name and choose the team member it is **Connected to** (**Kopplad till**). Optionally, under **Access rights for created objects** (**Behörighet för skapade objekt**), choose users and groups that get access to envelopes and deals created with the key.

The new key is shown only once, so store it securely. Keys do not expire. Deleting a key stops every integration that uses it immediately, so to rotate a key, create the new one, deploy it, then delete the old one. A team member cannot be removed from the team while an API key is connected to them.

## Use the key

The key is 64 characters long. Send it in the `x-resly-api-key` header:

```bash
curl https://api.resly.se/v2/envelopes \
  -H "x-resly-api-key: $RESLY_API_KEY"
```

The key acts as the team member it is connected to, within the team it was created for. If that member is a team admin, the key reaches all of the team's objects, such as envelopes and deals. Otherwise it only reaches objects shared with that member or their groups: list endpoints leave out the others, and operations on them return `403`. Read-only shares allow reading an object but not changing it. Objects created with the key are owned by the connected member and shared only with the users and groups set under the key's access rights for created objects. The team's default access setting does not apply to them.

If the header is missing, is not 64 characters, or is unknown, the API responds with `401 Unauthorized` and the `code` `ERROR_UNAUTHORIZED`. For a missing header, the body looks like this (trimmed):

```json
{
  "status": 401,
  "code": "ERROR_UNAUTHORIZED",
  "title": "Unauthorized",
  "detail": "Unable to authenticate. Check your API key.",
  "errors": [
    {
      "path": "/v2/envelopes",
      "message": "'x-resly-api-key' header required"
    }
  ]
}
```

Keep the key on your server. Never put it in browser or mobile app code.

## Test teams

There is no sandbox: every request works on live data, and publishing sends real invitations and counts toward your team's e-sign usage. To check a request body without live effects, call [Create and Publish Envelope](https://resly.readme.io/reference/createandpublishenvelope) with `dryrun=true`: it validates the request and returns `{}` without creating an envelope, sending invitations or counting toward usage. It does not check PDF contents or the free-plan e-sign limit, so a real request can still fail on those. To get a test team, contact Resly support at <support@resly.se>.

## Next steps

Follow [Getting started](https://resly.readme.io/reference/create-your-first-envelope) to create and publish your first envelope, and see [HTTP status codes](https://resly.readme.io/reference/http-status-codes) for error handling.