---
title: "API Authentication"
description: "Generate tokens and authenticate HTTP API requests to your Prismic repository."
meta_title: "API Authentication"
audience: developers
lastUpdated: "2026-09-18T14:49:53.000Z"
---

Prismic uses tokens to authenticate API requests. The token you need depends on whether you are reading or writing content.

# Write tokens

Write tokens authenticate requests to the Types, Asset, and Migration APIs. In documentation and the API, these are also called **permanent tokens** or **bearer tokens**.

> **Caution**
>
> <CalloutHeading>Be Careful!</CalloutHeading>
>
> Write tokens carry many privileges. Keep them secure and do not share them in publicly accessible areas such as GitHub, client-side code, and so forth.

Send your repository ID in the `repository` header and your write token in the `Authorization` header as a **Bearer** token (this is not [HTTP Basic Authentication](http://en.wikipedia.org/wiki/Basic_access_authentication)):

```auto
--header 'repository: repo-name' \
--header 'Authorization: Bearer <token>'
```

Make all API requests over **[HTTPS](http://en.wikipedia.org/wiki/HTTP_Secure)**. Calls made over plain HTTP or without authentication will fail.

## Generate a write token

Use the [Prismic CLI](https://prismic.io/docs/cli.md) to create a write token:

```sh
npx prismic token create --write
```

The command prints the generated bearer token. You can create multiple tokens for different applications.

You can also generate and manage write tokens under **Settings** → **API & Security** → **Write APIs** in your repository.

## APIs that use write tokens

| API           | Documentation                                                                 |
| ------------- | ----------------------------------------------------------------------------- |
| Types API     | [Types API](https://prismic.io/docs/custom-types-api.md)                      |
| Asset API     | [Asset API](https://prismic.io/docs/asset-api-technical-reference.md)         |
| Migration API | [Migration API](https://prismic.io/docs/migration-api-technical-reference.md) |

# Access tokens

Access tokens authenticate requests to the [Content API](https://prismic.io/docs/content-api.md) when your repository API is private. See [Content visibility](https://prismic.io/docs/fetch-content.md#content-visibility) for API access levels.

Generate one with the [Prismic CLI](https://prismic.io/docs/cli.md):

```sh
npx prismic token create
```

Then configure your client to use it. See the [Next.js](https://prismic.io/docs/nextjs.md#secure-with-an-access-token), [Nuxt](https://prismic.io/docs/nuxt.md#secure-with-an-access-token), or [SvelteKit](https://prismic.io/docs/sveltekit.md#secure-with-an-access-token) guide for step-by-step instructions.

You can also manage access tokens under **Settings** → **API & Security** in your repository. Learn more in [Repository settings](https://prismic.io/docs/repository-settings.md#api-and-security).

> **Important**
>
> The access token is a secret. Do not use it in client-side requests to prevent exposing the token.
