Skip to Content

Docs

Authentication

One kind of credential, an API key, for the REST API, the CSV export and the MCP server.

API Keys

Create keys in Account → API. A key is shown in full once, when you create it; AlphaScout stores only a SHA-256 hash, so a lost key can't be recovered, only replaced.

RuleDetail
Formatas_live_ followed by 32 characters
ScopeOne workspace. Everyone on a team shares its keys.
Who can manageThe workspace's owner and admins
How manyUp to 10 active keys per workspace
RevokingImmediate. A revoked key is refused on its next request.
AccessIncluded with every active plan. It lapses with the subscription.

When a Key Is Refused

A missing, unknown or revoked key, or one whose workspace has no active plan, gets 401 with this body and a WWW-Authenticate: Bearer realm="alphascout" header:

401
{
  "error": {
    "code": "invalid_api_key",
    "message": "Pass a valid key: Authorization: Bearer as_live_…"
  }
}

Restricting a Key

Two optional limits, set when you create a key in Account → API:

  • Allowed addresses. Up to 20 IP addresses or networks (203.0.113.7, 198.51.100.0/24, 2001:db8::/32). The key is refused from anywhere else with 403 ip_not_allowed, so a leaked key is useless outside your servers.
  • Expiry. 30, 90, 180 or 365 days. After that the key returns 401 key_expired; create a new one.

The key list shows each key's limits and the address it was last used from, so an unexpected one stands out.

Automatic Protection

Besides the rate limits, keys are watched for the patterns of a leak or of harvesting. The thresholds are far above any real integration. When one is crossed the workspace's owners and admins get an e-mail (at most once a day per key and reason).

PatternThresholdWhat happens
Many addresses10 different addresses in a day (warning), 40 (pause)E-mail at 10; paused for an hour at 40 (403 key_paused)
Unknown keys30 unknown keys in 10 minutes from one addressThat address is refused for 15 minutes (429 too_many_failures)
Data volume150,000 rows a day, exports included429 data_volume until 00:00 UTC
Walking ids150 company profiles requested in id orderThe key is paused for an hour (403 key_paused)
Profile harvest3,000 different company profiles in a dayE-mail only

A paused key resumes by itself. If you did nothing wrong, wait for Retry-After, or tell us. Use list endpoints with filters, since or the CSV export instead of fetching profiles one by one.

Good Practice

  • One key per integration, named for it, so you can revoke one without touching the rest.
  • Rotate keys when people leave the team.
  • Watch "last used" in the API page: an old key that is suddenly busy is worth a look.
  • Report anything that looks like a vulnerability to the address in security.txt.