Crawly
Documentation menu
Get started

Authentication

Authenticate Crawly requests with API keys, dashboard sessions, or Clerk OAuth.

API keys

Create a key in Dashboard → API keys and send it as a Bearer token. The secret is displayed once and should stay in your server-side secret store.

Authorization: Bearer ck_live_...

Account attribution

Personal keys use the personal plan and balance. Keys created while an organization is active use that organization’s plan, balance, Usage history, and limits.

Dashboard sessions

The Playground and dashboard use the signed-in Clerk session and the same credit and plan policy as API-key requests.

OAuth

Remote MCP clients can authorize through Crawly’s Clerk-hosted OAuth flow. The token maps to the approving Crawly user and uses that account’s policy.

Note: An invalid, expired, or revoked credential returns 401. It never silently downgrades to anonymous access.