Home / Docs / API keys

API keys and authentication

Every API call carries an API key. Make as many as you like, one per app or agent, and cap what each can spend.

Sending your key

API keys start with gw_. Send one in either header:

Shell
curl https://stackgrep.com/api/collections -H "Authorization: Bearer gw_..."
# or
curl https://stackgrep.com/api/collections -H "X-API-Key: gw_..."

A call without a valid key gets 401 with {"error": "sign in, or send an API key (Authorization: Bearer gw_...)"}.

Making and revoking keys

Keys are made on the API keys page of your dashboard. A key is shown once, when it's made; we keep only a hash of it. Make one per app or agent: they're free and unlimited, and each shows when it was last used.

Revoking a key stops it within seconds.

Capping what a key can spend

Every key draws on your team's one pool of credits. To keep one app or agent from using it all, give its key a monthly cap on the API keys page: past the cap, its calls get 402 while your other keys carry on.

MCP clients sign in with OAuth

Clients that connect to the MCP server with OAuth (Claude.ai, for one) don't need a key pasted in: you sign in and approve them, and each approved client gets its own key, listed on the API keys page, where revoking it ends the connection. Their access tokens only open the MCP server, not the REST API.

Try it on your own documentsExact and regex search for your agents, from one API. Or see the engine on npm's source first.