> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kirafin.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Access

> What Kira gives you before you can write any code, and how to ask for it.

Nothing here is self-serve. There is no sign-up form and no console that issues credentials — Kira provisions everything, and you cannot start until it has.

Ask for both pieces at once. Each is provisioned by a person, so requesting them one at a time adds a wait each time.

## What to ask for

<CardGroup cols={2}>
  <Card title="API credentials" icon="key">
    An API key, a client id and a client password, for the environment you are starting in.
  </Card>

  <Card title="Dashboard access" icon="table-columns">
    A login for the people who will watch payments, register webhook endpoints and answer compliance requests.
  </Card>
</CardGroup>

Your webhook endpoints are not on that list. You register those yourself, in the dashboard.

## The three credentials, and what each is for

| You are given   | Used as                | Where it appears                               |
| --------------- | ---------------------- | ---------------------------------------------- |
| API key         | The `x-api-key` header | Every call, including the one that logs you in |
| Client id       | Part of the login body | Only the token call                            |
| Client password | Part of the login body | Only the token call                            |

The client id and password are exchanged for a token. The API key is not — it goes on every request regardless.

<Warning>
  Sandbox and production credentials are different, and a sandbox key will not work against production. Everyone starts in sandbox; production credentials are issued separately, once you go live.
</Warning>

## Your webhook endpoints

Endpoints are self-serve. You register them in the **Developers** section of the dashboard, and you can register more than one — each event type goes to exactly one URL, so how you split them across endpoints is your choice. [Webhooks overview](/webhooks/overview) has the rules that govern them.

There are no `/v1` endpoints for any of this. The API cannot read or change an endpoint.

Register at least one before you start, because several things in the flow only ever announce themselves by webhook. An integration that waits until the end to think about webhooks will get to a payment stuck in an in-between state with nothing telling it why.

## What Kira will ask you for

To provision the above, expect to supply:

* **Who needs dashboard access**, and which [role](/dashboard/roles) each of them starts with.
* **Which environment you are starting in.** Everyone starts in sandbox.

## When you have it

Check the credentials work before writing anything else — that is one call, and it is the next page.

<Card title="Authentication" icon="arrow-right" href="/get-started/authentication">
  Exchange your credentials for a token and make an authenticated call.
</Card>
