Getting started
Authentication
Create, store, rotate, and send Yep API credentials safely.
API keys
The public REST API uses an API key as a Bearer token. Create a key in the product and copy its secret when it is shown. Yep does not show the full secret again.
Authorization: Bearer <API_KEY> Keep keys in a secret manager or environment variable. Do not put a key in browser code, a URL, source control, logs, or documentation examples.
Key lifecycle
Use a separate key for each application and environment so access can be revoked without interrupting unrelated workloads.
When rotating a key:
- Create the replacement key.
- Deploy the replacement to every instance.
- Confirm requests succeed with the replacement.
- Revoke the previous key.
MCP authentication
The remote MCP server accepts OAuth only, not API keys. Start authentication from your MCP client and complete the authorization flow in the browser. Search tools require search:read. Model, query-builder, and agent tools require both search:read and agent:run; agent:run is never granted by itself.
Next, integrate the Search API over HTTP or choose an MCP client.