# auth.md

CoinAPI authenticates agents and applications with an API key. This site does not expose OAuth on www.coinapi.io.

## Audience

AI agents, MCP clients, and applications that call CoinAPI Market Data, Exchange Rates, Indexes, Flat Files, or related APIs.

## Registration

Create an API key in the CoinAPI Console:

https://console.apibricks.io/?link=/apikeys/create

Human-readable authentication docs:

https://www.coinapi.io/products/market-data-api/docs/authentication

## Methods

Preferred method for agents and MCP clients:

`X-CoinAPI-Key: YOUR_API_KEY`

REST also accepts:

- Query parameter: `apikey=YOUR_API_KEY`
- URL path segment: `/APIKEY-YOUR_API_KEY`
- Authorization header: `Authorization: YOUR_API_KEY`
- HTTP Basic: username `coinapi`, password `YOUR_API_KEY`
- Optional JWT: `Authorization: Bearer <jwt>` after importing a public key in the Console

Hosted MCP servers use the same API key in the `X-CoinAPI-Key` request header:

- https://mcp.md.coinapi.io/mcp
- https://mcp.indexes.coinapi.io/mcp
- https://mcp.flatfiles.coinapi.io/mcp

## Credential use

Treat the API key as a secret. Do not embed it in public client-side code unless JWT authentication is also enabled. Store it in the agent or server environment and send it only to CoinAPI endpoints.
