# Authentication

Public price and volume endpoints need no credentials. Other endpoints list the
authentication methods they accept.

## API keys

Use an API key to access your own account. Send the complete key in
`x-bb-api-key`. Keys can have trading and bitcoin withdrawal permissions and IP
restrictions.

Order creation, cancellation, and bitcoin withdrawals require a nonce and
signature in addition to the API key. See
[API keys and signing](https://barebitcoin.no/developers/authentication/api-keys).

## OAuth

Use OAuth for supported third-party access. The endpoint lists the scopes that
its access token needs. Send the token as
`Authorization: Bearer <access token>`.

OAuth is available only on the operations that list it. An API-key permission is
not an OAuth scope. See the [OAuth guide](https://barebitcoin.no/developers/authentication/oauth).

## Selecting an authentication method

Where an endpoint accepts alternatives, use one complete method. Do not combine
bearer-token and API-key headers. Switching the method in the reference changes
the corresponding request example.


Source: https://barebitcoin.no/developers/authentication
