# Authentication (/authentication)



The two APIs authenticate differently.

## Official API [#official-api]

Official operations take a bearer token issued from the
[BUFF developer console](https://buff.163.com/developer).

```http
Authorization: Bearer <token>
```

Access is tiered. Each operation states whether it needs Developer or Enterprise access, along with
its update frequency and request limit.

## Internal API [#internal-api]

Internal operations have no documented credential. Some answer anonymous requests; others require
the cookies of a signed-in BUFF session, sent in the `Cookie` header.

```http
Cookie: session=<redacted>
```

Keep those cookies server-side. A route that rejects an anonymous request returns an
application-level `Login Required` in `msg` rather than an HTTP `401`.
