REST API Authentication
All REST API requests require an API key passed in theX-API-Key header.
Getting Your API Key
1
Go to the API Keys page
2
Create a new key
Click “Create API Key”
3
Copy and store your key
Copy and store your key securely
Using Your API Key
Pass your API key when making requests. The Python SDK readsTINYFISH_API_KEY from your environment automatically:
Environment Variables
Store your API key in an environment variable:.env file:
MCP Authentication
The MCP endpoint uses OAuth 2.1 for secure authentication with AI assistants.How It Works
1
Add the TinyFish MCP server
Add the TinyFish MCP server to your AI client configuration. See the MCP Integration guide for setup instructions.
2
Authenticate in browser
When you first use the tool, a browser window opens for authentication
3
Log in
Log in with your TinyFish account
4
Start using TinyFish Web Agent
Authorization is cached for future sessions
You need a TinyFish account with an active subscription or credits. Sign up here.
Error Responses
Authentication errors return standard HTTP status codes with a JSON error body. See Error Codes for the full reference.403 Forbidden — Insufficient Credits
403 Forbidden — Insufficient Credits
Authentication succeeded, but you lack credits or an active subscription.How to fix:
- Check your account at agent.tinyfish.ai/api-keys
- Add credits or upgrade your plan
Security Best Practices
Use Environment Variables
Never hardcode API keys in source code
Rotate Keys Regularly
Regenerate keys periodically and after team changes
Limit Exposure
Use separate keys for development and production
Monitor Usage
Review API usage in your dashboard for anomalies
Related
Quick Start
Run your first automation
Error Codes
Full error code reference