Keys and limits

    1. 1

      Rate and quota

      Each key has a per-minute rate, between 1 and 600, and an optional monthly quota. Over either, the answer is a 429 with a Retry-After header. Fetching the schema is free; only calls that read data count.

    2. 2

      Origins

      A key can list the web origins allowed to use it. The check runs only when a request carries an Origin header, so server-to-server calls always pass and an empty list means server-only. A browser calling from an origin not on the list gets a 403 that says exactly that.

    3. 3

      Expiry and revocation

      Keys can expire on a date, and can be revoked immediately. Either way the next call gets a 401 naming which of the two happened.

    4. 4

      The call log

      Every call is recorded: which tool, which operation, whether it was refused. The last hundred are in the dashboard.

    5. 5

      Your own tracing

      Send a W3C traceparent header and the call joins your trace: the reply's traceresponse header names our span in it, and the call log keeps your trace id, so a call found in Datadog, Grafana, AWS X-Ray or Google Cloud Trace can be found in the dashboard by searching for that id. Every reply also carries an X-Request-Id to quote if something went wrong.

    6. 6

      Calls in your observability tool

      Under Developers → Observability, an owner can send every tool call to an OpenTelemetry endpoint as a span, once a minute, over OTLP/HTTP with JSON: your Collector, or any backend that takes it. A call that sent traceparent appears inside your agent's trace. A span carries the operation, status, duration, result count, release, tool and key name; never what was searched for, a filter, or a record. Headers such as an API key are stored encrypted and never shown again. After ten failed sends in a row the export pauses until it's saved again, and the calls in between are sent then.