# Autenticazione

`GET /v1/connections`

Ogni chiamata a /v1 porta l'header `Authorization: Bearer <tu API key>`. La key ha il formato `wc_live_…` e si crea nel pannello (API keys). Viene mostrata UNA sola volta quando la crei — salvala. Se manca o non è valida, l'API risponde 401 con `code` `API_KEY_MISSING` (header assente/malformato, bug di integrazione) o `API_KEY_INVALID` (key non valida o revocata → ruotala nel pannello).

## Esempi

### cURL

```bash
# Every /v1 request needs: Authorization: Bearer <your API key>.
# A missing/invalid key → 401 { "error": { "code": "API_KEY_MISSING" | "API_KEY_INVALID" } }
curl https://api.waiaconnect.com/v1/connections \
  -H "Authorization: Bearer wc_live_YOUR_API_KEY"
```

### Node.js

```javascript
const res = await fetch("https://api.waiaconnect.com/v1/connections", {
  headers: { "Authorization": "Bearer wc_live_YOUR_API_KEY" }
});
if (res.status === 401) throw new Error("Check/rotate your API key in the panel");
console.log(await res.json()); // { connections: [ { id: "conn_…", … } ] }
```

### PHP

```php
<?php
$ch = curl_init("https://api.waiaconnect.com/v1/connections");
curl_setopt_array($ch, [
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_HTTPHEADER => ["Authorization: Bearer wc_live_YOUR_API_KEY"],
]);
$body = curl_exec($ch);
$code = curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($code === 401) { throw new Exception("Check/rotate your API key in the panel"); }
echo $body;
```

### Python

```python
import requests
res = requests.get("https://api.waiaconnect.com/v1/connections",
  headers={"Authorization": "Bearer wc_live_YOUR_API_KEY"})
res.raise_for_status()  # 401 → check/rotate your API key in the panel
print(res.json())  # {"connections": [{"id": "conn_…", ...}]}
```

## Note

- Il `code` è il contratto (per il tuo `switch`); il `message` in inglese è un aiuto per gli umani.
- La API key non compare mai in questa schermata: è salvata come hash lato server. Copia la tua da API keys.
