Authentication
Send your API key as a Bearer token, and the rate limits that apply to it.
Every request needs an API key. Send it as a Bearer token:
Authorization: Bearer tapi_…or in the X-Api-Key header. Keys start with tapi_. Create and revoke them under API keys; a revoked key stops working within a minute.
Keep keys on the server
Anyone with your key spends your credits. Keep it in an environment variable, not in browser code or a public repository.
A missing or unknown key gets 401:
{
"error": {
"code": "unauthorized",
"message": "Invalid or revoked API key.",
"retryable": false
}
}MCP clients can sign in with OAuth instead of a key; see MCP server.
Rate limits
Limits apply per key and rise with the largest pack the account has bought:
| Account | Requests | Burst |
|---|---|---|
| No pack bought yet | 1 per second, 100 per day (UTC) | 20 |
| $9 pack | 300 per minute | 50 |
| $29 pack | 600 per minute | 100 |
| $79 pack | 1,000 per minute | 150 |
Over the limit, the API answers 429 with rate_limited and a Retry-After header in seconds. A free key that has used its 100 requests for the day gets 429 daily_limit_reached until 00:00 UTC; any pack removes the daily limit. Need more? Contact us.