> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hopae.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate the Verification REST API and the OIDC token endpoint with your App ID and App Secret.

Every app has an **App ID** and an **App Secret**. Find both in the [Console](https://console.hopae.com) under **Developers → API Settings**.

| Where | How | Credentials |
| :- | :- | :- |
| Verification REST API (`/connect/v2/...`) | `Authorization: Basic base64(appId:appSecret)` | App ID + App Secret |
| OIDC `/v2/auth` | `client_id` query parameter | App ID |
| OIDC `/token` | HTTP Basic (`client_secret_basic`) or form fields (`client_secret_post`) | App ID + App Secret |

In OIDC terms, the App ID is your `client_id` and the App Secret is your `client_secret`.

<Warning>
  Keep the App Secret on your backend. Never put it in a browser bundle, a mobile app, or a public repository. If it leaks, contact [support@hopae.com](mailto:support@hopae.com) to rotate it.
</Warning>

Sandbox and production apps have separate credentials. See [Apps & Environments](/v2/guides/concepts/apps).

## Example

```bash theme={null}
curl "https://api.hopae.com/connect/v2/connections" \
  -u "APP_ID:APP_SECRET"
```

`-u` builds the Basic header for you. In the API playground, enter the App ID as the username and the App Secret as the password.

## Troubleshooting

| Error | Cause |
| :- | :- |
| `401 AUTH_INVALID_CREDENTIALS` | Wrong App ID or App Secret, or a scheme other than Basic |
| `404` on a verification you created | Another app's credentials, or the verification is past its `expiresAt` |
| `invalid_client` at `/token` | The secret is missing or does not belong to the `client_id` |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.