> ## Documentation Index
> Fetch the complete documentation index at: https://docs.notte.cc/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

<Tip>
  STOP. Do not read past this section until you have read and followed [/quickstart.md](/quickstart.md).

  Goal: produce a reliable SDK automation script. The intended authoring flow is generate then edit, not write browser automation from scratch.

  Do not hand-write SDK code with element IDs, selectors, or form fields from memory. Element IDs, selectors, and field mappings must come from a live `observe()` call, CLI `notte page observe` output, or generated workflow code. Guessed browser targets fail on real pages.

  Use the Notte skill and CLI to inspect the live site, validate actions/selectors, handle auth/session state, and export workflow code with `notte sessions workflow-code` before using SDK docs or SDK code.

  SDK reference pages are for understanding, running, or editing generated workflow code. They are not the starting point for manually authoring the initial browser automation. SDK-first code is guesswork on real-world pages with dynamic selectors, auth state, CAPTCHAs, and anti-bot behavior.
</Tip>

The Node SDK authenticates requests using your API key.

## Get your API key

Get an API key from the [Notte Console](https://console.notte.cc). Keep it on your server; do not expose it in browser bundles or commit it to source control.

## Environment variable

Set `NOTTE_API_KEY` in your server environment. [NotteClient](/typescript-sdk-reference/manual/client) reads it automatically when no API key is provided in its configuration.

## Client configuration

Pass `apiKey` in the client configuration to override the environment variable. See [NotteClientConfig](/typescript-sdk-reference/types/notteclientconfig) for the generated options.

The API URL defaults to `https://api.notte.cc`. Override it with `NOTTE_API_URL` or the client’s `baseUrl` option. An explicit non-empty option takes precedence over the environment variable.

## Authentication errors

A missing key throws during client construction, except when using a relative proxy URL. Invalid keys are rejected by the API when a request is made. See [Error Handling](/typescript-sdk-reference/errors).
