API keys
One API key works for both MCP and the REST API. A key only acts on your own account and stops working the moment you revoke it.
Creating a key
- Settings → API → New key;
- Name it ("Claude Code", "Cursor", "my script");
- Copy it — it's shown only once.
Your email must be verified to create keys.
Authenticating
Authorization: Bearer wk_<key>
Managing keys
- The list shows each key's name, creation time and last use;
- Revoking is immediate and permanent;
- Use one key per client — losing one doesn't affect the rest.
Rate limits
- 60 requests per minute per account (shared across MCP and REST);
- Agent turns charge actual model cost in credits (see Credits);
- Create-style calls accept an
Idempotency-Key header — the same key runs at most once within 24 hours.