Authentication
Every API, GraphQL, MCP, and A2A request needs a credential from a free account. Pick the option that fits:
| Method | Best for | How |
|---|---|---|
| API key | Scripts, servers, notebooks | Create one on My tracker. Up to 10 active keys per account. |
| OAuth 2.1 | MCP clients (Claude, ChatGPT) and apps acting for a user | Authorization code with PKCE and dynamic client registration. Server metadata. |
| Agent registration | An AI agent that needs its own key | The agent requests a key by email, you approve, and it claims the key. See auth.md. |
Send the key
Send the credential in the Authorization header. X-API-Key: <key> also works.
curl https://www.chicagopolitics.org/api/v1/me \
-H "Authorization: Bearer $CHICAGO_POLITICS_KEY"
GET /me returns your account, limits, and usage today, and doesn't count against your limits.
Keep keys secret
- Call the API from a server, not from a browser or mobile app, where anyone can read the key.
- Never put keys in URLs, and never commit them to source control. Use environment variables or a secrets manager.
- Use a separate key for each app so you can revoke one without breaking the others. Revoke a key on My tracker; it stops working right away.
- Limits are per account, so every key and connected app shares one daily allowance.