> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lendflow.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication Overview

## Authentication Overview

Lendflow uses bearer token authentication for API requests. The type of token you should use depends on whether you are connecting an external integration or authenticating a temporary user session.

Include the selected token in the `Authorization` header:

```http theme={"system"}
Authorization: Bearer <token>
```

## Choose an Authentication Method

### Integration Tokens

Use an Integration Token for:

* Lendflow MCP
* External AI agents
* Server-to-server integrations
* Scripts and scheduled automations
* Long-running services that should not store a user's password

Integration Tokens have configurable permissions, expiration, and rate limits. They can be edited or revoked independently without changing a user's password or ending their dashboard session.

For new external integrations, use an Integration Token when the required API actions are available in its permission list.

[Create and manage Integration Tokens](/lendflow-external/docs/integration-tokens)

### Login Bearer Tokens

Use the authentication endpoints when your application needs to start a temporary session using a Lendflow user's email and password.

Login bearer tokens:

* Represent the authenticated user
* Expire after two hours
* Can be refreshed through the Refresh Access Token endpoint
* Require your application to securely handle user credentials and token refresh

Do not use a login flow for Lendflow MCP or an unattended integration when an Integration Token supports the required actions.

* [Get Bearer Token](/api-reference/authentication/get-bearer-token)
* [Refresh Access Token](/api-reference/authentication/refresh-access-token)

### Legacy Static API Bearer Tokens

Some existing integrations may still use a static API bearer token from the dashboard.

<Warning>
  Do not use a legacy static API bearer token for a new integration. Use an Integration Token where supported so access can be scoped, monitored, expired, and revoked independently.
</Warning>

Before migrating an existing integration, confirm that its required API actions are available in the Integration Token permission list. Test the replacement token before revoking the existing credential.

## Common Authentication Scenarios

### Connecting Lendflow MCP

Create a dedicated Integration Token with the **Mcp Server Tools** permission group. Add it to the MCP client's `Authorization` header.

[Connect Lendflow MCP](/lendflow-external/docs/connect-lendflow-mcp)

### Running a Backend Integration

Create a dedicated Integration Token for the service. Select only the permissions required by that integration and store the token in a server-side secret manager.

Use a separate token for each integration so that one connection can be rotated or revoked without affecting another.

### Authenticating a Temporary User Session

Use the Get Bearer Token endpoint, send the returned token with API requests, and refresh it before it expires. Never expose the user's password or bearer token in client-side logs.

### Using the Lendflow Dashboard

The Lendflow dashboard manages its own authenticated session. You do not need to manually create or provide an Integration Token for normal dashboard use.

## Permissions and Data Access

A token does not grant more access than its user already has.

For an API request to succeed:

1. The token must be active and valid.
2. An Integration Token must include the permission required by the endpoint.
3. The associated user role must allow the action.
4. The user must have access to the requested client, deal, or other resource.

A token may authenticate successfully but still be unable to perform an action if one of these authorization checks fails.

## Store Tokens Securely

* Store tokens in a secret manager or protected server environment variable.
* Never place tokens in frontend code, mobile applications, screenshots, or shared documents.
* Never commit tokens to source control.
* Use one Integration Token per external integration.
* Grant only the permissions the integration needs.
* Set an expiration when practical.
* Revoke and replace a token immediately if it may have been exposed.
* Avoid writing tokens to application or request logs.

## Authentication Errors

### `401 Unauthorized`

The token is missing, incomplete, expired, revoked, or otherwise invalid. Confirm the `Authorization: Bearer <token>` header and the token's current status.

### `403 Forbidden`

The token is valid, but its permissions or the associated user's role do not allow the requested action.

### `429 Too Many Requests`

The request exceeded the applicable rate limit. Wait for the limit to reset or review the Integration Token's configured rate limit.

## Recommended Setup

1. Identify whether the connection is an external integration or a temporary user session.
2. Create an Integration Token or obtain a login bearer token as appropriate.
3. Store the credential securely.
4. Test a read-only API request.
5. Add only the additional permissions required by the integration.
6. Document how the token will be rotated and revoked.

## Next steps

<Card title="Integration Tokens" icon="fingerprint" href="/lendflow-external/docs/integration-tokens" horizontal>
  Create, permission, and revoke a token in the Lendflow Dashboard.
</Card>

<Card title="Connect Lendflow MCP" icon="plug" href="/lendflow-external/docs/connect-lendflow-mcp" horizontal>
  Use an Integration Token to connect an MCP client.
</Card>

<Card title="Errors" icon="circle-exclamation" href="/api-docs/docs/errors" horizontal>
  Read status codes and the `message` / `errors` body on a failed request.
</Card>

<Card title="Getting Started with Lendflow" icon="rocket" href="/lendflow-external/docs/getting-started" horizontal>
  Authenticate, submit an application, and embed the Application Widget or Borrower Platform.
</Card>
