docs
docs

API keys

Keys authenticate every request and carry your account's buyback token and Reward Status.

  • Keys look like xk_live_ab12cd34_.... The part after xk_live_ up to the next underscore is the key's public id, shown in your dashboard.
  • The full key is shown once, at creation. We store only a keyed hash of it.
  • Send it as Authorization: Bearer <key>. SDKs do this for you from api_key.
  • Create one key per app or agent, so you can see usage per key and revoke one without touching the others.
  • Revoking a key takes effect within a minute.
  • Rate limits: every key can make up to 600 requests per minute. The limit is set by the platform and is the same for every key; it cannot be changed per key. See errors & rate limits.

Never put a key in client-side code. Coding agents can sign in instead of holding a key (see MCP sign-in).