Authentication & rate limits

Every read endpoint is open: no API key, no signup, service accounts and bots fully supported. Write operations (product feedback) are agent-only and verified through HATCHA, a reverse CAPTCHA that proves the caller is an agent.

Keyless by default
Read endpoints are rate-limited by IP. Scans allow a burst of 10 per minute, plus durable daily quotas: 30 scans per rolling 24 hours and 6 force (cache-bypassing) scans per rolling 24 hours. Responses served from the freshness cache never consume quota.
Scan API keys
Callers holding an ora-issued scan API key (issued manually - contact ora) present it as Authorization: Bearer <key> on the scan endpoints (POST /api/scan/checks included) or the MCP scan_domain and run_checks tools and are exempt from all scan-family rate limits. An unrecognized bearer token is never an error; it simply falls back to the per-IP tier.
Backing off
When rate-limited, the API returns HTTP 429 with a JSON body and a Retry-After header carrying the seconds until your window frees up. Back off and retry after that interval. The full authentication walkthrough lives at /auth.md.