<!-- Generated by scripts/build_openapi_skill_references.py; do not edit. -->
# OpenAPI contract: API authentication

## Provenance

- Source: `ycloud-api-v2.yaml` (pinned release snapshot).
- Source SHA-256: `8592bd4cc37186655a480dd86ce6bac6731543727327a2871d9103a0b8ed9e81`
- OpenAPI version: `3.0.0`
- API info.version: `v2`
- This derived reference does not replace the upstream API Owner's canonical source.
- Generated deterministically from normalized JSON; do not edit this file by hand.

## Scope and handoff

- The source declares one global `api_key` security scheme: send a placeholder value in the `X-API-Key` header from a trusted server. This reference never reads, validates, echoes, or stores a real key.
- Operation coverage: `0`

## Authentication contract

- Global security requirement: `api_key`.
- Scheme: `apiKey`, header name `X-API-Key`.
- Use a placeholder such as `<YCLOUD_API_KEY>` in examples; never read or verify a real secret.
- Keep the key server-side, out of browsers/mobile clients, URLs, logs, repositories, and customer data.

## Codegen interpretation

- `api_key` and `X-API-Key` are raw HTTP contract facts. Do not infer an SDK auth helper or package version from this document.
- This OpenAPI snapshot does not define cross-cutting runtime behavior. Consult the reviewed `runtime.md`; if neither source confirms a fact, do not fill it in.
