Sending your key
API keys start with gw_. Send one in either header:
curl https://stackgrep.com/api/collections -H "Authorization: Bearer gw_..."
# or
curl https://stackgrep.com/api/collections -H "X-API-Key: gw_..."A call without a valid key gets 401 with {"error": "sign in, or send an API key (Authorization: Bearer gw_...)"}.
Making and revoking keys
Keys are made on the API keys page of your dashboard. A key is shown once, when it's made; we keep only a hash of it. Make one per app or agent: they're free and unlimited, and each shows when it was last used.
Revoking a key stops it within seconds.
Capping what a key can spend
Every key draws on your team's one pool of credits. To keep one app or agent from using it all, give its key a monthly cap on the API keys page: past the cap, its calls get 402 while your other keys carry on.
MCP clients sign in with OAuth
Clients that connect to the MCP server with OAuth (Claude.ai, for one) don't need a key pasted in: you sign in and approve them, and each approved client gets its own key, listed on the API keys page, where revoking it ends the connection. Their access tokens only open the MCP server, not the REST API.