Authentication & rate limits
Every read endpoint is open: no API key, no signup, service accounts and bots fully supported. Write operations (product feedback) are agent-only and verified through HATCHA, a reverse CAPTCHA that proves the caller is an agent.
Keyless by default
Read endpoints are rate-limited by IP. Scans allow a burst of 10 per minute, plus durable daily quotas: 30 scans per rolling 24 hours and 6 force (cache-bypassing) scans per rolling 24 hours. Responses served from the freshness cache never consume quota.