# API key

> What an API key is, how it differs from an ingest key and from OAuth, and how the read-only MIRA FIVE REST API uses personal API keys.

URL: https://mirafive.io/glossary/api-key  
Updated: 2026-09-28

An API key is a secret credential that lets a program read data from a service on your behalf, within the rights the key was given.

An API key identifies a program to a service. The program sends the key with each request, and the service answers with the data that key may see. Anyone holding the key gets that access, so it belongs in a server’s configuration or a secrets manager and never in a web page.

OAuth is the alternative for tools that act for a person. Instead of copying a key, the person signs in, approves the connection and can withdraw it later. It is the usual choice for assistants and third-party apps.

## In MIRA FIVE

The public REST API v1 at `https://app.mirafive.io/api/v1` is read-only. It covers projects, the overview, people and a single person, events, goals, funnels, acquisition channels, Google Search Console data and Google Ads. It accepts personal API keys or OAuth, at up to 120 requests a minute. The [Model Context Protocol (MCP)](https://mirafive.io/glossary/mcp) server for Claude and other agents signs in with OAuth or an API key. Sending events uses different credentials, the [ingest keys](https://mirafive.io/glossary/ingest-key) of a source: a website key for browsers and a secret key for servers.

## Read next

### Related terms

- [Ingest key](https://mirafive.io/glossary/ingest-key)
- [Model Context Protocol (MCP)](https://mirafive.io/glossary/mcp)
- [Insight](https://mirafive.io/glossary/insight)
- [Dashboard](https://mirafive.io/glossary/dashboard)

[All terms](https://mirafive.io/glossary)

## See which channel brings buyers

Free for 25,000 events a month. No card needed.

[Start free](https://app.mirafive.io/register)[See pricing](https://mirafive.io/pricing)
