> ## Documentation Index
> Fetch the complete documentation index at: https://pitchprint.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> How your API Key and Secret Key work, and how to sign Runtime API requests.

Every call to the Runtime API is authenticated with a signature generated from your domain's keys. Get both keys from the [Domains page](https://admin.pitchprint.io/domains) in your PitchPrint admin.

| Key | Where it runs |
| - | - |
| **API Key** | Public-facing. Identifies your domain on each request. |
| **Secret Key** | Server-side only. Used to build the signature. Never sent in a request. |

<Danger>
  Never expose your Secret Key in client-side code, a public repository, or a mobile app bundle. Anyone holding it can edit your PitchPrint account. Use it only from your server.
</Danger>

## Generate a signature

Append your **API Key + Secret Key + timestamp** and take the MD5 hash of the resulting string. That hash is your signature. The timestamp is a UNIX timestamp (seconds since the epoch) and is valid for a one-hour window, so generate a new signature for each request.

<Warning>
  Protect the script that generates your signature so that only code with the right privileges can call it, since it has access to your Secret Key.
</Warning>

<CodeGroup>
  ```php PHP theme={null}
  <?php
      define('PITCH_APIKEY', 'your-api-key');
      define('PITCH_SECRETKEY', 'your-secret-key');

      function generateSignature () {
          $timestamp = time();
          $signature = md5(PITCH_APIKEY . PITCH_SECRETKEY . $timestamp);
          return array ('timestamp'=>$timestamp, 'apiKey'=>PITCH_APIKEY, 'signature'=>$signature);
      }
  ?>
  ```

  ```javascript Node.js theme={null}
  const md5 = require('md5'); // you need the md5 module

  function generateSignature () {
    const timestamp = Math.floor(Date.now() / 1000);
    const apiKey = 'your-api-key';
    const secretKey = 'your-secret-key';
    const signature = md5(apiKey + secretKey + timestamp);
    return { timestamp, apiKey, signature };
  }
  ```
</CodeGroup>

## Sending the request

Send `apiKey`, `timestamp` and `signature`, plus any endpoint-specific fields, as a JSON body. The endpoint for all runtime calls is **[https://api.pitchprint.io/runtime/](https://api.pitchprint.io/runtime/)**.

<Note>
  Pass the parameters as a JSON string, not query-string pairs. For example: `curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($opts));`
</Note>

## Related articles

<CardGroup cols={2}>
  <Card title="Fetch Design" icon="file-code" href="/docs/api-reference/fetch-design">
    Retrieve the source data for a single design by its designId.
  </Card>

  <Card title="Fetch Designs" icon="list" href="/docs/api-reference/fetch-designs">
    List all designs under a given category.
  </Card>

  <Card title="Fetch Project" icon="file-code" href="/docs/api-reference/fetch-project">
    Retrieve the source data for a single project by its projectId.
  </Card>

  <Card title="Clone Project" icon="clone" href="/docs/api-reference/clone-project">
    Clone an existing project associated with your domain.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.