Grail

Authentication

Every request is authenticated with a Bearer API key. Keys are instant, self-serve, and commercial use is included.

Bearer keys

Pass your key on every request:

Authorization: Bearer ***

A missing or invalid key returns 401 {"error":"unauthorized"}. A valid key that is over its quota returns 429.

Create an account

Sign in or create a free account at grail.solutions/login. Your first API key is ready the moment you land in the dashboard — no approval queue.

Manage keys

Create, rotate and revoke keys from the dashboard. Rotation mints a replacement and revokes the old key atomically.

A revoked key stops authenticating against /v1 on the next request.

Sessions & security

The dashboard is secured by a hosted identity provider (email confirmation, magic links, password reset). Account endpoints require a valid session and fail closed — unauthenticated callers get 401.