# Authentication

> **Warning:** Since September 25, 2026, new school API keys can no longer be created. Integrations that already have a key keep using it. New integrations must use [API v3](https://cademi.dev/api/authentication.md), which has its own credentials.

Every call carries the school API key in the `Authorization` header. The `Bearer` prefix is optional. It is the same key as [API v1](https://cademi.dev/api/v1/authentication.md).

```http
GET /api/v2/user/email:maria@exemplo.com/access
Host: yourschool.cademi.com.br
Authorization: Bearer 4cc58d97-14c2-406f-a8c5-1ebb8e05696d
```

The key identifies the school and is valid for the whole school. Deleting it in the dashboard revokes it immediately. Without the header, or with a key that does not exist or was deleted, the answer is HTTP 401:

```json
{ "code": 401, "success": false, "message": " Invalid api key" }
```
