# Authentication

Source: https://wire.ia.br/documentation/en/api/autenticacao

> The token header, account confirmation with the ID and the language of the answers.



Every request carries the token in the `Authorization` header:

```http
GET /api/v1/vaults HTTP/1.1
Host: wire.ia.br
Authorization: Bearer paper_k3m9x2ab_Q7wLc2…
X-Paper-Account: 3f2a9c…(account ID, 32 characters)
Accept-Language: en
```

## Account confirmation [#account-confirmation]

The `X-Paper-Account` header is optional and recommended. It carries the ID of the account that owns the token, shown in **Settings → Developer** and in **Settings → Profile**.

If the ID doesn't match the token's owner, the request fails with `403`, without touching anything. This keeps an agent from using, by mistake, someone else's token left in a history, an old file or the wrong conversation.

AI agents should always send this header.

## Language of the answers [#language-of-the-answers]

Error messages come in the language of `Accept-Language`: `pt-BR` (default), `en` or `es`. JSON field names don't change.

## What's checked on every request [#whats-checked-on-every-request]

1. The token format.
2. Whether the token exists, wasn't revoked and hasn't expired (`401` if not).
3. Whether the account exists, isn't banned, has developer mode on and has accepted the current API terms (`403` if not).
4. Whether `X-Paper-Account` matches the account (`403` if not).
5. The per-minute and per-day limits (`429` if exceeded). See [Limits](/en/api/limites).
6. Whether the token has permission for the request's vault, calendar or attachments (`403` if missing).

## Good practices [#good-practices]

* Always use `https://`. A request to `http://` is redirected, but the token has already traveled unprotected.
* Don't send the token as a URL parameter. It shows up in logs and histories.
* Keep the token out of the code: environment variable, secrets manager or password vault.
