# Authentication

How to create an Atlas account, retrieve your API keys, and authenticate API requests.

Atlas authenticates your requests using API keys. To get your API keys, you need to create an account for free on the [Atlas sign up page](https://atlas-app.tryduplo.com/auth/signup). After sign-up, you will be **required to submit [compliance documents](https://docs.tryduplo.com/atlas/guides/compliance#required-documents-and-details)** before you can go live.

Info

You can use Atlas in **test mode** while your documents are under review. Test mode lets you explore the API without affecting live balances or real payments.

## [Getting your API keys](https://docs.tryduplo.com/en/atlas/guides/auth#getting-your-api-keys)

1. Log in to the **Atlas Dashboard**.
2. Open **Settings** → **Developer**.
3. Copy your **API keys**.

Warning

- **Never** embed your API key in client-side code or mobile apps.
- Store it in server-side environment variables (for example, `ATLAS_API_KEY`).
- Use **test keys** in development and **live keys** only in production.

## [Authenticating requests to the API](https://docs.tryduplo.com/en/atlas/guides/auth#authenticating-requests-to-the-api)

The Atlas API follows the [Representational State Transfer (REST)](https://en.wikipedia.org/wiki/REST) standard to organize its API. It accepts and returns [JSON-encoded](http://www.json.org/) data and uses standard HTTP response codes, authentication, and verbs.

The keys shown in your dashboard depend on your account mode. If your account is in test mode, you will see test keys; if it’s in live mode, you will see live keys. Test mode requests don’t affect your live data or interact with the banking networks.

### [Base URL](https://docs.tryduplo.com/en/atlas/guides/auth#base-url)

The base URL for Atlas is the same for all environments. There is no separate test or production URL, the API key you use determines whether your request runs in test mode or live mode.

The Base URL for all requests is:

Atlas Base URL

```
https://atlas.tryduplo.com/
```

The requests are authenticated using the **Bearer Token** authentication scheme. For every request you send, you need to include an `Authorization` header with the value `Bearer <YOUR_API_KEY>`.

For example:

cURL

```
curl https://atlas.tryduplo.com/ \
  -H "Authorization: Bearer pk_test_123" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json"
```

Tip

For added security, we recommend [encrypting your request payloads](https://docs.tryduplo.com/atlas/guides/encryption).

## [Related guides](https://docs.tryduplo.com/en/atlas/guides/auth#related-guides)

- [Compliance and Verification](https://docs.tryduplo.com/atlas/guides/compliance)
- [Configure and Verify Webhooks](https://docs.tryduplo.com/atlas/guides/webhooks)
- [Encrypting Atlas Payloads](https://docs.tryduplo.com/atlas/guides/encryption)
- [Go-Live Checklist](https://docs.tryduplo.com/atlas/guides/go-live)

Last updated on 5/11/2026
