Docs
Authentication
One kind of credential, an API key, for the REST API, the CSV export and the MCP server.
API Keys
Create keys in Account → API. A key is shown in full once, when you create it; AlphaScout stores only a SHA-256 hash, so a lost key can't be recovered, only replaced.
| Rule | Detail |
|---|---|
| Format | as_live_ followed by 32 characters |
| Scope | One workspace. Everyone on a team shares its keys. |
| Who can manage | The workspace's owner and admins |
| How many | Up to 10 active keys per workspace |
| Revoking | Immediate. A revoked key is refused on its next request. |
| Access | Included with every active plan. It lapses with the subscription. |
Sending the Key
Use the standard Bearer header on every request. Keys are never accepted in the URL.
Authorization: Bearer as_live_…When a Key Is Refused
A missing, unknown or revoked key, or one whose workspace has no active plan, gets 401 with this body and a WWW-Authenticate: Bearer realm="alphascout" header:
{
"error": {
"code": "invalid_api_key",
"message": "Pass a valid key: Authorization: Bearer as_live_…"
}
}Restricting a Key
Two optional limits, set when you create a key in Account → API:
- Allowed addresses. Up to 20 IP addresses or networks (
203.0.113.7,198.51.100.0/24,2001:db8::/32). The key is refused from anywhere else with403 ip_not_allowed, so a leaked key is useless outside your servers. - Expiry. 30, 90, 180 or 365 days. After that the key returns
401 key_expired; create a new one.
The key list shows each key's limits and the address it was last used from, so an unexpected one stands out.
Automatic Protection
Besides the rate limits, keys are watched for the patterns of a leak or of harvesting. The thresholds are far above any real integration. When one is crossed the workspace's owners and admins get an e-mail (at most once a day per key and reason).
| Pattern | Threshold | What happens |
|---|---|---|
| Many addresses | 10 different addresses in a day (warning), 40 (pause) | E-mail at 10; paused for an hour at 40 (403 key_paused) |
| Unknown keys | 30 unknown keys in 10 minutes from one address | That address is refused for 15 minutes (429 too_many_failures) |
| Data volume | 150,000 rows a day, exports included | 429 data_volume until 00:00 UTC |
| Walking ids | 150 company profiles requested in id order | The key is paused for an hour (403 key_paused) |
| Profile harvest | 3,000 different company profiles in a day | E-mail only |
A paused key resumes by itself. If you did nothing wrong, wait for Retry-After, or tell us. Use list endpoints with filters, since or the CSV export instead of fetching profiles one by one.
Good Practice
- One key per integration, named for it, so you can revoke one without touching the rest.
- Rotate keys when people leave the team.
- Watch "last used" in the API page: an old key that is suddenly busy is worth a look.
- Report anything that looks like a vulnerability to the address in security.txt.