sk_...) exists for MCP only.
Session bearer token (primary method)
The web app authenticates via an httpOnly session cookie set at login — not a client-readable token, so browser JS never calls a session-fetching API directly. Server-side route handlers read the verified session and forward it as a bearer token to the API:API key (MCP only)
A long-livedsk_... API key authenticates the MCP endpoint specifically — it is not accepted by any other route today:
Rate limits
Rate limits are applied per route category, not per plan — every workspace on every plan (Free, Starter, Pro, Business, Enterprise) gets the same limits today:
See Rate Limits & Pagination for the full breakdown.