Skip to content
Getting started

Authentication

API keys, scopes, and server-side credentials.

The DeepSearch API uses scoped bearer keys for server-to-server authentication.

Bearer API keys

Create a key in the developer portal. Pass it in the Authorization header, store it in server secrets, and never expose it in a browser bundle. A key is shown in full only once.

Authorization header
curl https://deepsearch.app/api/v1/search \
  -H "Authorization: Bearer $DEEPSEARCH_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "query": "Ada Lovelace" }'

Scopes

Each key carries scopes that gate which endpoints it can call. New keys are granted all three by default, but production keys can be narrowed to only the endpoints they need and can be given an expiry date or per-key minute limit.

ScopeEndpoints
searchPeople search, Reverse-image search, Company search
dossierPerson dossier, Company dossier, VIN lookup
chatPerson chat

A request with a missing or revoked key returns 401; a valid key without the required scope returns 403.