Keys and limits
- 1
Rate and quota
Each key has a per-minute rate, between 1 and 600, and an optional monthly quota. Over either, the answer is a 429 with a
Retry-Afterheader. Fetching the schema is free; only calls that read data count. - 2
Origins
A key can list the web origins allowed to use it. The check runs only when a request carries an
Originheader, so server-to-server calls always pass and an empty list means server-only. A browser calling from an origin not on the list gets a 403 that says exactly that. - 3
Expiry and revocation
Keys can expire on a date, and can be revoked immediately. Either way the next call gets a 401 naming which of the two happened.
- 4
The call log
Every call is recorded: which tool, which operation, whether it was refused. The last hundred are in the dashboard.
- 5
Your own tracing
Send a W3C
traceparentheader and the call joins your trace: the reply'straceresponseheader names our span in it, and the call log keeps your trace id, so a call found in Datadog, Grafana, AWS X-Ray or Google Cloud Trace can be found in the dashboard by searching for that id. Every reply also carries anX-Request-Idto quote if something went wrong. - 6
Calls in your observability tool
Under Developers → Observability, an owner can send every tool call to an OpenTelemetry endpoint as a span, once a minute, over OTLP/HTTP with JSON: your Collector, or any backend that takes it. A call that sent
traceparentappears inside your agent's trace. A span carries the operation, status, duration, result count, release, tool and key name; never what was searched for, a filter, or a record. Headers such as an API key are stored encrypted and never shown again. After ten failed sends in a row the export pauses until it's saved again, and the calls in between are sent then.