# API and authentication Every route has four faces: HTML, JSON, documentation and (where selected) an assistant tool. Ask for JSON with `Accept: application/json`. ## Authentication Resolution order: 1. `session` cookie (64 hex characters) after logging in at `/auth/login`. 2. `X-API-KEY` header with your API key. 3. `Authorization: Bearer `. 4. `Authorization: Basic` with name or email and password. There is no JWT and no OAuth. ## Example ```bash curl -H 'Accept: application/json' https://molodetz.nl/roll ``` ## Errors Errors have the shape `{"error": {"status": 404, "message": "..."}}`. Validation errors return `422` with `{"error": "validation", "fields": [...], "messages": [...]}`. ## Old paths The Dutch paths from before (`/rol`, `/standaard`, `/mensen`, `/binnen`, `/voorwaarden`) answer with a 301 to their English replacement. Query strings are kept.