Docs · Keys, tiers and limits
Keys, tiers and limits
A free account holds one active key; Developer accounts hold up to ten and a Licence up to 25, one per app or environment. Keys are shown once, can be rotated with a 24-hour overlap, and are revoked instantly.
Updated 2026-10-02
Getting a key
- Sign in at /keys with Google or a one-time email link.
- Create a key with an optional label (production, ci, my-laptop). Creating a key accepts the pre-release developer terms shown under the button.
- Copy it now. The full key is shown once. The keys page later shows only the prefix.
Tiers
| Free | Theory Pro | Developer | Licence | |
|---|---|---|---|---|
| Calls a month | 1,000 | 10,000 | 100,000 | 1,000,000 |
| Calls a minute | 60 | 120 | 300 | 1,000 |
| Active keys | 1 | 2 | 10 | 25 |
| Price | Free, no card | $5 a month, founder rate locked for life until Dec 31, 2026 | $20 a month, founder rate locked for life until Dec 31, 2026 | $1,200 a year, commercial use of the MCP server. Get the licence |
| How to get it | Create a key | Sign in at /keys and pick a plan. Payment is by card through Stripe; the account's keys move to the new limits within a minute | ||
Every tier is a hard cap: at the limit the API answers 429 quota_exceeded until the month resets on the first. Cancelling a plan drops the keys back to the free limits at once. Keys issued under the earlier Builder tier have the Developer limits.
T.H.I.R.I. Builders on Skool is the community: the Monday repo show, the Thursday call, the ship logs and the private repos. It does not change a key's tier.
Rate limits
- Per key, per minute: 60 on free, 120 on Theory Pro, 300 on Developer, 1,000 on Licence. Exceeding it returns
429 rate_limitedwith a message naming the tier. - Per IP: an additional throttle protects the service from unauthenticated floods. Normal use never meets it.
- Monthly quota: every successful
/v2call counts one. Failed calls (4xx) do not. WatchX-Quota-UsedandX-Quota-Limiton each response.
{
"error": "quota_exceeded",
"message": "Monthly quota of 1000 calls reached on the free tier. ..."
} Rotate and revoke
Rotate when a key may have leaked or on a schedule. A new key is issued immediately and the old one keeps working for 24 hours so you can roll deployments. Revoke stops a key at once; anything using it fails with 401 from that moment. Both live on /keys.
# Rotate from the keys page (/keys) or, with a signed-in session,
# POST https://keys.thiri.ai/v2/keys/{id}/rotate
# The old key keeps working for 24 hours, then stops. Handling the key safely
- Store it in an environment variable or your client's config. Never in a repo, a screenshot or a shared prompt.
- Browser apps: the key is visible to anyone who opens dev tools. Put a tiny proxy in front of the API for anything public, or ask for a scoped key.
- On Developer or Licence, one key per app. If one leaks, you rotate one thing.
- Anonymized usage (volumes, latency, error rates) is logged to run the service. Query bodies are logged to improve the engine's vocabulary; do not send secrets in chord names.
About sign-in
The keys page signs you in with a one-time email link. If the link does not arrive within a minute, check spam, then try again; if it keeps failing, email dennison@bluesprincemedia.com and we will sort it out by hand.
Next
Errors →
Every error code the API returns and what to do about it.