Skip to main content
Most MCP clients connect to Syrto by signing you in with OAuth - you add the server URL and follow the login prompt, as described in Setup. That needs a person at the keyboard. For scripts, scheduled jobs, CI pipelines and server-to-server integrations, the Syrto MCP server also accepts an organization API key sent as a bearer token. No sign-in flow runs; the key is checked on every request.

Sign-in or API key

Create a key

API keys are created by an organization admin in the Syrto dashboard, under Settings → API keys. They are the same organization keys used by the Syrto API, so a key you already have for the API works here too. Keys begin with sk_. Treat a key like a password: it grants access to your organization’s data and consumes its usage. Keep it in a secret store or an environment variable, never in a URL, a prompt, or a file you commit.
Only organization keys are accepted. The personal keys you can create under Profile → API keys are refused with 401 Unauthorized, because an API key is meant to identify an organization rather than a person. To use Syrto as yourself, sign in with OAuth instead.

Send the key

Point your client at the Syrto MCP server and send the key in the Authorization header:
The examples below read the key from a SYRTO_API_KEY environment variable:
Add the server with a fixed Authorization header:
Your shell expands $SYRTO_API_KEY when you run the command, so Claude Code stores the key itself in its configuration.

What an API key cannot do

An organization key carries no person, so the tools for official documents, person contacts and personal usage are not offered on a key connection: They are left out of the tool list, and calling one anyway returns an error saying the tool needs a signed-in user. Every other tool works with a key, including company and person search, company profiles, structure, metrics and analysis.

Rate limits and usage

The rate limits apply to the organization as a whole when you use an API key: every key belonging to the organization draws on one shared set of limits, so creating more keys does not raise them. Plan for this before pointing a high-volume pipeline at a key. Usage made with a key is billed to the organization’s Syrto AI allowance, just like usage from signed-in members.

Revoke a key

An admin deletes keys from the same Settings → API keys page in the dashboard. A deleted or expired key stops working within about a minute.

Errors

A key that is not accepted always gets 401 Unauthorized. The usual causes:
  • No Authorization header, or it is not in the form Bearer sk_....
  • The key is mistyped, deleted, or expired.
  • The key is a personal key from Profile → API keys rather than an organization key.