Docs / Getting started
Authentication
Every request carries your API key as a bearer token.
The header
1Authorization: Bearer grape_...Each account has one key. It can search your projects and read their briefs, and nothing else. Send it from your server, never from a web page, because anyone who sees it can search your projects.
Rotating the key
Press New key on the API keys page. The old key, and every MCP URL built from it, stops working at once.