# missing_key

Source: https://capacms.com/docs/errors/missing_key

401 authentication. The request carried no x-api-key header.

| HTTP status | `type`           | Surfaces      |
| ----------- | ---------------- | ------------- |
| 401         | `authentication` | REST, GraphQL |

## What it means

The request carried no x-api-key header.

| When                  | What the `hint` tells you                                           |
| --------------------- | ------------------------------------------------------------------- |
| no `x-api-key` header | no hint on REST: send the header, with a key from Developers > Keys |

## What to do

Send the key in x-api-key.

## The response

HTTP 401:

```json
{
  "error": {
    "type": "authentication",
    "code": "missing_key",
    "message": "An API key is required. Send it in the x-api-key header.",
    "docs": "https://docs.capacms.com/errors/missing_key"
  },
  "meta": {
    "version": "2026-10-01",
    "contract": 1,
    "requestId": "req_0f3c…"
  }
}
```

## On GraphQL

`/api/graphql` answers the same `code` inside `errors[].extensions`. The status depends on the `Accept` header you send ([status codes](https://capacms.com/docs/api/graphql#status-codes)):

| `application/json` | `graphql-response+json` | When                                |
| ------------------ | ----------------------- | ----------------------------------- |
| 401                | 401                     | no key, or a key Capa does not know |

## See also

* [Keys and scopes](https://capacms.com/docs/api/authentication)
