# Authentication

The AutoCoder API has two integration paths. Each path has its own authentication.

## Direct API (primary)

The direct AutoCoder API is the main way to send coding tasks to HANK. It runs on AWS behind `https://services.hank.ai`. Authenticate every request with your customer API key in the `x-api-key` header:

```http
POST /autocoding/v1/tasks/ HTTP/1.1
Host: services.hank.ai
x-api-key: <your-api-key>
Content-Type: application/json
```

Your Hank.ai representative provisions the key for your organization. The key scopes every request to your organization, so your data stays isolated from every other customer. Keep the key server-side. Do not commit it to source control. Do not send it from a browser.

## Hank Codes console (secondary)

The Hank Codes console offers a separate, console-managed coding API for organizations that integrate through the console instead of the direct API. That path uses a bearer token that the console issues, and a different request format. See the console documentation for its contract. Do not mix the two: the direct API does not accept bearer tokens, and the console API does not accept `x-api-key`.

## Which path do I use?

| You are | Use |
| --- | --- |
| Integrating a billing or EHR system with HANK autocoding | The direct API (`services.hank.ai`, `x-api-key`) |
| Working inside the Hank Codes console or its managed workflows | The console path (bearer token) |

If you are not sure, ask your Hank.ai representative. Most API integrations use the direct API.
