Authentication

Every API, GraphQL, MCP, and A2A request needs a credential from a free account. Pick the option that fits:

MethodBest forHow
API keyScripts, servers, notebooksCreate one on My tracker. Up to 10 active keys per account.
OAuth 2.1MCP clients (Claude, ChatGPT) and apps acting for a userAuthorization code with PKCE and dynamic client registration. Server metadata.
Agent registrationAn AI agent that needs its own keyThe agent requests a key by email, you approve, and it claims the key. See auth.md.

Send the key

Send the credential in the Authorization header. X-API-Key: <key> also works.

curl https://www.chicagopolitics.org/api/v1/me \
  -H "Authorization: Bearer $CHICAGO_POLITICS_KEY"

GET /me returns your account, limits, and usage today, and doesn't count against your limits.

Keep keys secret