# Authentication



Every request needs an API key. Send it as a Bearer token:

```http
Authorization: Bearer tapi_…
```

or in the `X-Api-Key` header. Keys start with `tapi_`. Create and revoke them under [API keys](https://stage.threadapi.dev/app/api-keys?utm_source=docs); a revoked key stops working within a minute.

<Callout type="warn" title="Keep keys on the server">
  Anyone with your key spends your credits. Keep it in an environment variable, not in browser code or a public repository.
</Callout>

A missing or unknown key gets `401`:

```json
{
  "error": {
    "code": "unauthorized",
    "message": "Invalid or revoked API key.",
    "retryable": false
  }
}
```

MCP clients can sign in with OAuth instead of a key; see [MCP server](/mcp).

Rate limits [#rate-limits]

Limits apply per key and rise with the largest pack the account has bought:

| Account            | Requests                        | Burst |
| :----------------- | :------------------------------ | ----: |
| No pack bought yet | 1 per second, 100 per day (UTC) |    20 |
| $9 pack            | 300 per minute                  |    50 |
| $29 pack           | 600 per minute                  |   100 |
| $79 pack           | 1,000 per minute                |   150 |

Over the limit, the API answers `429` with `rate_limited` and a `Retry-After` header in seconds. A free key that has used its 100 requests for the day gets `429 daily_limit_reached` until 00:00 UTC; any pack removes the daily limit. Need more? [Contact us](https://stage.threadapi.dev/contact?utm_source=docs).
