# Configure authentication

## Use a server-side API key

```ts
import { createClient } from "@qentrah/sdk";

const cms = createClient({
  url: "https://cms.example.com",
  apiKey: process.env.QENTRAH_API_KEY,
});
const health = await cms.system.health();
```

The API key is an application secret. Keep privileged keys in server code. The client also accepts `token`, optional `tenant`, custom `headers`, and an injected `fetch` function.

## Sign in with credentials

```ts
const cms = createClient({ url: "https://cms.example.com" });
const session = await cms.auth.login({
  email: "editor@example.com",
  password: suppliedPassword,
});
```

`suppliedPassword` is application input, not a hard-coded sample password. Login returns a token and user record. The client’s auth resource updates its authentication state; your application owns secure persistence and session lifetime.

## Replace client credentials

```ts
cms.setToken(savedToken);
cms.setApiKey(serverApiKey);
```

Resource operations may also accept a per-request `RequestAuth` object containing `apiKey` or `token`. Apply server permissions as well as UI restrictions.

## Sign out

```ts
await cms.auth.logout();
```

Clear the corresponding application session and cached privileged data according to your host application’s authentication design.