Skip to main content

API Key Authentication

All REST endpoints require an API key passed in the X-API-KEY header. REST does not use OAuth. The MCP server uses OAuth for ChatGPT custom connectors. Claude, Cursor, and other header-based MCP clients use the same API key as REST.

Getting Your API Key

You can find your API key in your Octanist dashboard under Settings → API / MCP.
Make sure you are in the correct organization. The API key is organization-specific and if you get the wrong API key, you might see leads going to the wrong organization or other unwanted behavior.

Using Your API Key

Include your API key in the X-API-KEY header with every REST request:
Claude, Cursor, and other header-based MCP clients send that same key as X-API-KEY or as Authorization: Bearer. Do not put the key in the URL. ChatGPT connectors use OAuth instead. See MCP.

Security Best Practices

Keep your API key secure and never expose it in client-side code or public repositories.
  • Store your API key in environment variables
  • Rotate your API keys regularly
  • Monitor API usage for unusual activity