API key
An API key is a secret credential that lets a program read data from a service on your behalf, within the rights the key was given.
An API key identifies a program to a service. The program sends the key with each request, and the service answers with the data that key may see. Anyone holding the key gets that access, so it belongs in a server’s configuration or a secrets manager and never in a web page.
OAuth is the alternative for tools that act for a person. Instead of copying a key, the person signs in, approves the connection and can withdraw it later. It is the usual choice for assistants and third-party apps.
In MIRA FIVE
The public REST API v1 at https://app.mirafive.io/api/v1 is read-only. It covers projects, the overview, people and a single person, events, goals, funnels, acquisition channels, Google Search Console data and Google Ads. It accepts personal API keys or OAuth, at up to 120 requests a minute. The Model Context Protocol (MCP) server for Claude and other agents signs in with OAuth or an API key. Sending events uses different credentials, the ingest keys of a source: a website key for browsers and a secret key for servers.