# Authentication

Every API, GraphQL, MCP, and A2A request needs a credential from a free account. Pick the option that fits:

| Method | Best for | How |
| --- | --- | --- |
| **API key** | Scripts, servers, notebooks | Create one on [My tracker](https://www.chicagopolitics.org/account). Up to 10 active keys per account. |
| **OAuth 2.1** | MCP clients (Claude, ChatGPT) and apps acting for a user | Authorization code with PKCE and dynamic client registration. [Server metadata](https://www.chicagopolitics.org/.well-known/oauth-authorization-server). |
| **Agent registration** | An AI agent that needs its own key | The agent requests a key by email, you approve, and it claims the key. See [auth.md](https://www.chicagopolitics.org/auth.md). |

## Send the key

Send the credential in the `Authorization` header. `X-API-Key: <key>` also works.

```bash
curl https://www.chicagopolitics.org/api/v1/me \
  -H "Authorization: Bearer $CHICAGO_POLITICS_KEY"
```

[GET /me](https://www.chicagopolitics.org/developers/api/get-me) returns your account, limits, and usage today, and doesn't count against your limits.

## Keep keys secret

- Call the API from a server, not from a browser or mobile app, where anyone can read the key.
- Never put keys in URLs, and never commit them to source control. Use environment variables or a secrets manager.
- Use a separate key for each app so you can revoke one without breaking the others. Revoke a key on [My tracker](https://www.chicagopolitics.org/account); it stops working right away.
- Limits are per account, so every key and connected app shares one daily allowance.

---
Source: https://www.chicagopolitics.org/developers/authentication · Chicago Politics, an independent, nonpartisan tracker of the Chicago City Council. Guide for agents: https://www.chicagopolitics.org/llms.txt
