# About Authentication (https://developer.godaddy.com/en/docs/api-users/auth)

---
title: About Authentication
description: >-
  How GoDaddy API authentication works — credential types, PAT scopes, and
  account eligibility requirements.
keywords: >-
  Bearer token, sso-key, OAuth, offline_access, reseller account, OTE
  credentials, token expiry, Authorization header
agentNotes:
  permissions:
    - Any account
  scopes:
    - 'domains.domain:read'
    - 'commerce.store:read'
    - 'shopping.catalog:read'
  rateLimit: >-
    API calls with PAT: rate-limited per credential per window. Go to
    /docs/api-users/rate-limits for current values.
  idempotent: true
  destructive: false
  failureRecovery: >-
    PAT reveals once at creation — if lost, revoke and regenerate. Revocation is
    instant across all edges.
related:
  guides:
    - title: How to Authenticate
      href: /docs/api-users/auth/how-to
    - title: Quickstart
      href: /docs/api-users/quickstart
    - title: Set up the CLI
      href: /docs/api-users/cli/set-up
    - title: About the Shopping API
      href: /docs/api-users/shopping
  concepts:
    - title: Handle errors
      href: /docs/api-users/errors
    - title: Rate limits
      href: /docs/api-users/rate-limits
---

## Overview

GoDaddy APIs support Bearer authentication through scoped Personal Access Tokens (PATs). Domains v3 requires a PAT.

The legacy `sso-key` credential remains required for Auctions and supported for Domains v1/v2. It is scheduled for Domains deprecation and does not work with v3.

Go to [How to Authenticate](https://developer.godaddy.com/docs/api-users/auth/how-to) for credential setup.

## Credential types

| Credential                  | Format                                                | Works with                                                                          | Status                                                       |
| --------------------------- | ----------------------------------------------------- | ----------------------------------------------------------------------------------- | ------------------------------------------------------------ |
| Personal Access Token (PAT) | `Authorization: Bearer $GODADDY_PAT`                  | Domains v3, Hosting, Shopping, and other PAT-enabled APIs; not accepted by Auctions | Recommended                                                  |
| Classic Developer Key       | `Authorization: sso-key $GODADDY_KEY:$GODADDY_SECRET` | Auctions API (required); Domains v1/v2                                              | Deprecated for Domains (through 2026); required for Auctions |

The Shopping API accepts PATs for direct API integrations.

A PAT has capability scopes, an optional expiration, and independent revocation. For most integrations, choose a PAT with the minimum required scopes.

## Account requirements

Some operations require the account to meet specific eligibility rules regardless of credential type. A valid credential on an ineligible account is still refused with a `403 Forbidden` response and an `Error` code that distinguishes the reason from a missing scope. Check the `code` field on the response body, not just the HTTP status, to determine the reason. Go to [Handle errors](https://developer.godaddy.com/docs/api-users/errors) for the full error envelope and status code reference.

| Operation group                                                                | Requirement                                                                                                                                                                                               |
| ------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Domain management (list, DNS, contacts, renewals, lock, privacy)               | Account holds at least one domain, OR is on a plan that grants management access.                                                                                                                         |
| Registration, renewal, transfer (any operation that costs money in production) | Account has a valid billing method on file or a funded [Good as Gold](https://www.godaddy.com/help/what-is-good-as-gold-3359) balance. Go to [Set up a payment profile](https://developer.godaddy.com/docs/api-users/payment-profile). |

## PAT scopes

A PAT is scoped to specific capabilities at generation time. Each scope enables a set of operations on a specific resource. A write scope satisfies read operations for the same resource; a read scope is refused on writes. Go to [Generate a PAT](https://developer.godaddy.com/docs/api-users/auth/how-to#generate-a-token) for step-by-step instructions.

### Commerce

Commerce APIs use the same PAT and grant model as Domains. When you generate a token, the **Commerce** categories display in the scope picker next to **Domains & DNS**. These cover catalog, orders, customers, tax, transactions, store, and channel operations. Select a category or expand it to grant a subset (for example `commerce.order:read`, `commerce.product:write`). Go to [Commerce API scopes](https://developer.godaddy.com/docs/references/rest/commerce-scopes) for the complete scope-to-endpoint reference.

### Domains

When you generate a token, the **Domains & DNS** bundle in the scope picker selects all scopes below. You can expand it to grant a subset instead.

| Scope                       | Required to                                                            |
| --------------------------- | ---------------------------------------------------------------------- |
| `domains.domain:read`       | Read domain records, availability, suggestions, quotes, and operations |
| `domains.domain:create`     | Register domains                                                       |
| `domains.domain:update`     | Modify domain settings                                                 |
| `domains.domain:delete`     | Delete or cancel domains                                               |
| `domains.dns:update`        | Create, update, and delete DNS zone records                            |
| `domains.nameserver:update` | Replace authoritative nameservers for a domain                         |
| `domains.host:update`       | Modify domain host records                                             |
| `domains.forward:update`    | Configure domain forwarding                                            |
| `domains.contact:update`    | Update registrant, admin, or tech contacts                             |
| `domains.transfer:execute`  | Initiate an inbound domain transfer                                    |
| `domains.transfer:update`   | Modify a transfer in progress                                          |

### Email

| Scope                  | Required to                      |
| ---------------------- | -------------------------------- |
| `email.mailbox:read`   | List and look up email mailboxes |
| `email.mailbox:create` | Create email mailboxes           |

### Shopping

| Scope                       | Required to                                                      |
| --------------------------- | ---------------------------------------------------------------- |
| `shopping.catalog:read`     | Search products, look up variants by ID, retrieve product detail |
| `shopping.checkout:execute` | Create, retrieve, update, and complete checkout sessions         |
| `shopping.order:read`       | Retrieve completed order detail                                  |

Go to [About the Shopping API](https://developer.godaddy.com/docs/api-users/shopping#authentication) for Shopping authentication and header requirements.

For `hosting.*` scopes used by the Hosting API, go to [Hosting core concepts](https://developer.godaddy.com/docs/api-users/hosting/concepts#scopes-reference) for the full scope list.
