# Response Codes

## `200      OK`

- **object**  
  - **secret**  
    - type: string  
      - The shared HMAC ASA secret

## `401`

| Error | Description |
| --- | --- |
| User has not been authenticated | Invalid or missing API key |
| API key is not active | The API key used is no longer active |
| Could not find API key | The API key provided is not associated with any user |
| Please provide API key in Authorization header | The Authorization header is not in the request |
| Please provide API key in the form Authorization: [api-key] | The Authorization header is not formatted properly |
| Insufficient privileges. Issuing API key required | Write access requires an Issuing API key. Reach out at [lithic.com/contact](/content/contact/index.html) |
| Insufficient privileges to create virtual cards. | Creating virtual cards requires an additional privilege |

## `429`

Client has exceeded the number of allowed requests in a given time period.

| Error | Description |
| --- | --- |
| Rate limited, too many requests per second | User has exceeded their per second rate limit |
| Rate limited, reached daily limit | User has exceeded their daily rate limit |
| Rate limited, too many keys tried | One IP has queried too many different API keys |

---

## Example Request

```shell
curl --request GET \
     --url https://sandbox.lithic.com/v1/auth_stream/secret \
     --header 'accept: application/json'
```

## Example Response

```json
{
  "secret": "whsec_1NDsYinMGr951KuDEaj78VtWzlyPaOnwUVagFiWIPJs="
}
```
