# Use a key

Send the key as Authorization: Bearer rfk_... on /api/v1/forms and the other /api/v1 routes. Those keys can create and update forms, list submissions, manage webhooks, and read analytics.

*API keys on the organization page.*

> The website authenticates with a session cookie. The hosted MCP server uses OAuth, then maps that grant to the same user. Do not send the session JWT as a Bearer API key. API keys and sign-in are separate. See MCP server if you want an assistant to sign in and edit forms.

## Sitemap

- Home: https://requestforms.io/
- Website forms: https://requestforms.io/website-forms
- Pricing: https://requestforms.io/pricing
- Docs: https://requestforms.io/docs
- Blog: https://requestforms.io/blog
- Tools: https://requestforms.io/tools
- OpenAPI: https://requestforms.io/openapi.json
- llms.txt: https://requestforms.io/llms.txt
- XML sitemap: https://requestforms.io/sitemap.xml
