API keys
Keys authenticate every request and carry your account's buyback token and Reward Status.
- Keys look like
xk_live_ab12cd34_.... The part afterxk_live_up to the next underscore is the key's public id, shown in your dashboard. - The full key is shown once, at creation. We store only a keyed hash of it.
- Send it as
Authorization: Bearer <key>. SDKs do this for you fromapi_key. - Create one key per app or agent, so you can see usage per key and revoke one without touching the others.
- Revoking a key takes effect within a minute.
- Rate limits: every key can make up to 600 requests per minute. The limit is set by the platform and is the same for every key; it cannot be changed per key. See errors & rate limits.
Never put a key in client-side code. Coding agents can sign in instead of holding a key (see MCP sign-in).