Authentication
Every request is authenticated with a Bearer API key. Keys are instant, self-serve, and commercial use is included.
Bearer keys
Pass your key on every request:
Authorization: Bearer ***A missing or invalid key returns 401 {"error":"unauthorized"}. A valid key that is over its quota returns 429.
Create an account
Sign in or create a free account at grail.solutions/login. Your first API key is ready the moment you land in the dashboard — no approval queue.
Manage keys
Create, rotate and revoke keys from the dashboard. Rotation mints a replacement and revokes the old key atomically.
A revoked key stops authenticating against /v1 on the next request.
Sessions & security
The dashboard is secured by a hosted identity provider (email confirmation, magic links, password reset). Account endpoints require a valid session and fail closed — unauthenticated callers get 401.