# Authentication

## Server-only rule

- Use the key from backend code only.
- Return product-shaped responses to the browser.
- Proxy file previews and downloads through authenticated product routes.
- Do not forward caller-controlled org, member, Workspace, or harness IDs without server-side validation.

**Open standard**  
This page's server-only Bearer rule is the client-side counterpart of UHP's credential requirements, which forbid a credential from ever appearing in a response body, event, log line, or artifact. See [credential rules in UHP's Security chapter](https://unifiedharnessprotocol.org/spec/security).

[Create API Key →](https://app.harnessrouter.ai/quickstart?ref=docs-create-api-key)

Ready to run this against a live workspace? Keys take under a minute.
