Docs / Getting started

Authentication

Every request carries your API key as a bearer token.

1Authorization: Bearer grape_...

Each account has one key. It can search your projects and read their briefs, and nothing else. Send it from your server, never from a web page, because anyone who sees it can search your projects.

Rotating the key

Press New key on the API keys page. The old key, and every MCP URL built from it, stops working at once.