Skip to content

Ctrl/⌘ K

Getting started

Authentication

Create, store, rotate, and send Yep API credentials safely.

API keys

The public REST API uses an API key as a Bearer token. Create a key in the product and copy its secret when it is shown. Yep does not show the full secret again.

Request http
Authorization: Bearer <API_KEY>

Keep keys in a secret manager or environment variable. Do not put a key in browser code, a URL, source control, logs, or documentation examples.

Key lifecycle

Use a separate key for each application and environment so access can be revoked without interrupting unrelated workloads.

When rotating a key:

  1. Create the replacement key.
  2. Deploy the replacement to every instance.
  3. Confirm requests succeed with the replacement.
  4. Revoke the previous key.

MCP authentication

The remote MCP server accepts OAuth only, not API keys. Start authentication from your MCP client and complete the authorization flow in the browser. Search tools require search:read. Model, query-builder, and agent tools require both search:read and agent:run; agent:run is never granted by itself.

Next, integrate the Search API over HTTP or choose an MCP client.

Commands