threadapiDocs

Authentication

Send your API key as a Bearer token, and the rate limits that apply to it.

Every request needs an API key. Send it as a Bearer token:

Authorization: Bearer tapi_…

or in the X-Api-Key header. Keys start with tapi_. Create and revoke them under API keys; a revoked key stops working within a minute.

Keep keys on the server

Anyone with your key spends your credits. Keep it in an environment variable, not in browser code or a public repository.

A missing or unknown key gets 401:

{
  "error": {
    "code": "unauthorized",
    "message": "Invalid or revoked API key.",
    "retryable": false
  }
}

MCP clients can sign in with OAuth instead of a key; see MCP server.

Rate limits

Limits apply per key and rise with the largest pack the account has bought:

AccountRequestsBurst
No pack bought yet1 per second, 100 per day (UTC)20
$9 pack300 per minute50
$29 pack600 per minute100
$79 pack1,000 per minute150

Over the limit, the API answers 429 with rate_limited and a Retry-After header in seconds. A free key that has used its 100 requests for the day gets 429 daily_limit_reached until 00:00 UTC; any pack removes the daily limit. Need more? Contact us.

On this page