> ## Documentation Index
> Fetch the complete documentation index at: https://docs.syrto.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# API keys

> Connect to the Syrto MCP server with an organization API key instead of signing in.

Most MCP clients connect to Syrto by signing you in with OAuth - you add the server URL and follow the login prompt, as described in [Setup](/mcp/setup). That needs a person at the keyboard.

For scripts, scheduled jobs, CI pipelines and server-to-server integrations, the Syrto MCP server also accepts an **organization API key** sent as a bearer token. No sign-in flow runs; the key is checked on every request.

## Sign-in or API key

| | Sign in (OAuth) | Organization API key |
| - | - | - |
| **Identifies** | You and your organization | Your organization only - no person |
| **Suited to** | AI assistants used by people | Scripts, automation, server-to-server integrations |
| **Tools available** | All | All except the [five that need a person](#what-an-api-key-cannot-do) |
| **Rate limits** | Counted per person | Shared by all of the organization's keys |
| **Usage billed to** | Your organization | Your organization |

## Create a key

API keys are created by an organization **admin** in the [Syrto dashboard](https://dashboard.syrto.ai/api-keys), under **Settings → API keys**. They are the same organization keys used by the [Syrto API](/api/authentication), so a key you already have for the API works here too.

Keys begin with `sk_`. Treat a key like a password: it grants access to your organization's data and consumes its usage. Keep it in a secret store or an environment variable, never in a URL, a prompt, or a file you commit.

<Warning>
  Only **organization** keys are accepted. The personal keys you can create under **Profile → API keys** are refused with `401 Unauthorized`, because an API key is meant to identify an organization rather than a person. To use Syrto as yourself, sign in with OAuth instead.
</Warning>

## Send the key

Point your client at the Syrto MCP server and send the key in the `Authorization` header:

```
URL:    https://mcp.syrto.ai/mcp
Header: Authorization: Bearer sk_...
```

The examples below read the key from a `SYRTO_API_KEY` environment variable:

```bash theme={null}
export SYRTO_API_KEY=sk_...
```

<Tabs>
  <Tab title="Claude Code">
    Add the server with a fixed `Authorization` header:

    ```bash theme={null}
    claude mcp add --transport http syrto https://mcp.syrto.ai/mcp \
      --header "Authorization: Bearer $SYRTO_API_KEY"
    ```

    Your shell expands `$SYRTO_API_KEY` when you run the command, so Claude Code stores the key itself in its configuration.
  </Tab>

  <Tab title="VS Code">
    Add the server to `.vscode/mcp.json`. The `inputs` entry makes VS Code ask for the key once and store it securely, so it never appears in the file:

    ```json theme={null}
    {
      "inputs": [
        {
          "type": "promptString",
          "id": "syrto-api-key",
          "description": "Syrto API key",
          "password": true
        }
      ],
      "servers": {
        "syrto": {
          "type": "http",
          "url": "https://mcp.syrto.ai/mcp",
          "headers": {
            "Authorization": "Bearer ${input:syrto-api-key}"
          }
        }
      }
    }
    ```
  </Tab>

  <Tab title="HTTP">
    Any MCP client or SDK that can send custom HTTP headers works the same way. To check a key from the command line, send an `initialize` request:

    ```bash theme={null}
    curl -s https://mcp.syrto.ai/mcp \
      -H "Authorization: Bearer $SYRTO_API_KEY" \
      -H "Content-Type: application/json" \
      -H "Accept: application/json, text/event-stream" \
      -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"curl","version":"1.0"}}}'
    ```

    A valid key returns the server's name and capabilities. A `401 Unauthorized` means the key was not accepted - see [Errors](#errors).
  </Tab>
</Tabs>

## What an API key cannot do

An organization key carries no person, so the tools for official documents, person contacts and personal usage are not offered on a key connection:

| Tool | Why it needs a person |
| - | - |
| [`syrto_list_official_documents`](/mcp/tools/official-documents#syrto_list_official_documents) | Reports the organization's credit balance, which is only available to a signed-in user |
| [`syrto_request_official_document`](/mcp/tools/official-documents#syrto_request_official_document) | Spends the organization's credits on someone's behalf |
| [`syrto_get_person_contacts`](/mcp/tools/person-contacts#syrto_get_person_contacts) | Records who looked a person up, and reports the credit balance |
| [`syrto_request_person_contacts`](/mcp/tools/person-contacts#syrto_request_person_contacts) | Spends the organization's credits on someone's behalf |
| [`syrto_get_usage`](/mcp/tools/usage) | Reports one person's own consumption |

They are left out of the tool list, and calling one anyway returns an error saying the tool needs a signed-in user. Every other tool works with a key, including company and person search, company profiles, structure, metrics and analysis.

## Rate limits and usage

The [rate limits](/mcp/setup#rate-limits) apply to the **organization as a whole** when you use an API key: every key belonging to the organization draws on one shared set of limits, so creating more keys does not raise them. Plan for this before pointing a high-volume pipeline at a key.

Usage made with a key is billed to the organization's Syrto AI allowance, just like usage from signed-in members.

## Revoke a key

An admin deletes keys from the same **Settings → API keys** page in the dashboard. A deleted or expired key stops working within about a minute.

## Errors

A key that is not accepted always gets `401 Unauthorized`. The usual causes:

* No `Authorization` header, or it is not in the form `Bearer sk_...`.
* The key is mistyped, deleted, or expired.
* The key is a personal key from **Profile → API keys** rather than an organization key.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.