> ## Documentation Index
> Fetch the complete documentation index at: https://docs.arena-predictions.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Send an arena_sk_ key as a bearer token. Scopes decide what it can read.

## Header

```http theme={null}
Authorization: Bearer arena_sk_…
```

Clients that cannot set `Authorization` may send `x-arena-key: arena_sk_…` instead. HTTPS only.

| Result | When |
| - | - |
| `401 unauthorized` | No credential. Carries `WWW-Authenticate: Bearer` with `error="invalid_request"`. |
| `401 invalid_token` | Key is malformed, unknown, revoked or expired. One answer for all four, on purpose. |
| `403 insufficient_scope` | Valid key without the scope the endpoint checks. Create a new key with it. |

## Scopes

| Scope | Grants |
| - | - |
| `records:read` | Public records: [`GET /leaderboard`](/api-reference/records/get-a-leaderboard), [`/traders/{traderId}`](/api-reference/records/get-a-trader), [`/traders/{traderId}/picks`](/api-reference/records/get-a-traders-settled-picks). |
| `portfolio:read` | The key owner's own account: [`GET /account`](/api-reference/portfolio/get-your-account), [`/portfolio`](/api-reference/portfolio/get-your-portfolio), [`/portfolio/trades`](/api-reference/portfolio/list-your-trades), [`/me/eval`](/api-reference/portfolio/get-your-own-eval-rows), and the owner's own `/traders/{traderId}/picks` with private picks included. |
| `markets:read` | Instruments and games: [`GET /instruments`](/api-reference/markets/list-instruments), `/instruments/search`, `/instruments/{ref}`, `/games`, `/games/{ref}`, and the quotes routes once [venue data](/conventions/privacy-and-venue-data#venue-data) is on. Keys created before this scope existed lack it. |
| `trade:write` | Reserved. Not issued in v1 (`403 scope_not_available`). Trade with the CLI or MCP server under your own login. |

[`GET /me`](/api-reference/identity/get-me) and [`GET /usage`](/api-reference/usage/get-usage) accept any valid key. [`GET /status`](/api-reference/status/get-status) needs none.

## Sessions

[Key management](/getting-started/api-keys#key-management-endpoints) uses a person's session instead of a key: the website's cookie, or a signed-in CLI's session token as the bearer. There is no guest or anonymous access.

<Note>
  The playground in the API reference sends requests through Mintlify's proxy. Use a key you can revoke, with only the scopes you need.
</Note>
