Sending the key
Pass your key in theX-API-Key header on every request:
?api_key= query string instead. See Streaming: WebSocket.
Key format and security
Keys look likeohlcv_<env>_sk_<48_random_chars> where <env> is live, dev, or test.
Keys are hashed (SHA-256) at rest. You see the full key once at generation. Lost a key? Rotate to issue a new one — there’s no way to retrieve the original. Rotation issues a fresh key and grants the old one a 7-day grace period before it stops working.
Tiers and RPS caps
Pricing is capped requests-per-second with unlimited monthly volume — pick a tier that matches your sustained throughput.
The cap is strict per second: requests are counted in fixed one-second windows, with no burst allowance above the cap. See Quotas & errors.
Some endpoints are tier-gated (
/tokens/{mint}/smart-money, /tokens/{mint}/whales). Free callers receive HTTP 200 with tier_locked: true rather than 429 — see Quotas & errors.
Inspecting your usage
CallGET /credits at any time to see your current tier, RPS cap, requests used in the current window, and feature flags:
Error responses
Errors are always enveloped, witherror as an object:
error.code; error.message is for humans. A few families are not on this shape yet: /swaps/* and /stats/* send error as a string code with a sibling message, and /tokens/{mint}/concentration sends error as a string. If error is a string, treat it as the message. See Quotas & errors for the per-family breakdown.
Full error catalog: see Quotas & errors.

