- Anonymous - no auth, three free read tools. Great for a quick answer.
- Connect (OAuth) - log in with your Reechee account in the browser, no key to paste. Best for MCP clients like Claude that support it. Tools follow your team’s current plan.
- API key - a bearer token you generate and manage. Best for scripts, servers, and agents that spend credits.
Anonymous
The free reads - product search, the pain-points taste, and competitors - need no authentication at all. Just call the REST endpoints or point an MCP client athttps://mcp.reechee.io/mcp. Anonymous access is read-only and
rate-limited by IP.
Connect (OAuth)
For MCP, you can connect with your Reechee account instead of a key. Point the client at:/mcp/auth URL. The bare https://mcp.reechee.io/mcp answers anonymously
(the 3 free tools) so a client that hits it never prompts you to log in. The /mcp/auth
variant returns a 401 that tells the client to run the OAuth flow. Same server, same
data - /mcp/auth just starts you at the login door.
Tools follow your plan. The connected token exposes exactly what your team’s current
plan allows, evaluated on every request: a free team gets the 3-tool taste tied to your
identity; a paid team gets the full read + action set (twelve tools). Upgrade and the paid
tools light up on the next connect or tool refresh. The three credit-spending tools
appear only if you allow an optional credit budget on the consent screen - a rolling
30-day ceiling on what the connection can spend (all fifteen tools). Leave it empty and
the connection can never spend your credits. The budget is fixed for the life of the
connection; to change it, disconnect and reconnect with a new one.
Token lifetime and disconnect. Access tokens are short-lived (1 hour) and the client
refreshes them automatically in the background; a refresh session lasts 30 days. Disconnect
from the client’s own connector settings whenever you like - it revokes the token
immediately, and the next request with it gets a 401. Reconnect any time by approving the
consent screen again.
OAuth Connect and API keys are independent. Connecting an MCP client doesn’t create or
need a key, and revoking one never affects the other. Pick per client: Connect for a
browser login, a key for headless use.
API key
Everything else - opportunities, full pain-point reports, the watchlist, credit balance, and write actions - needs a paid-team API key.Create a key
In the app, go to Settings → API keys and create one. Keys are available to paid teams (Starter and up). The full key is shown once, at creation - copy it then; it can’t be retrieved later. A key looks like:Use a key
Send it as a bearer token. For the REST API:get_pain_points returns the full report.
Revoke a key
Revoke a key any time from Settings → API keys. Revocation is immediate - the next request with that key gets a401.
Errors
A missing key on a protected endpoint, or an invalid, revoked, or expired key, returns401 unauthorized:
Keep keys server-side. Anyone with a key can act as your team within its limits. Treat
it like a password; rotate it (create a new one, revoke the old) if it leaks.