# Auth.md — Vast.ai Agent Authentication

Vast.ai API access uses account API keys.

## Credential handling

- Do not ask users to paste API keys into public pages.
- Do not expose secrets in logs, screenshots, pull requests, or analytics.
- Prefer environment variables or the official CLI/SDK authentication flow.
- Confirm the target account before taking any paid or destructive action.

## High-risk actions

Require explicit user confirmation before creating, stopping, destroying, or modifying instances, serverless endpoints, templates, billing settings, SSH keys, or host settings.

## References

- API keys: https://docs.vast.ai/guides/reference/keys.md
- Permissions: https://docs.vast.ai/api-reference/permissions.md
- API catalog: https://vast.ai/.well-known/api-catalog
