Authentication
Authenticate requests with organization-scoped API keys.
Send your API key as a Bearer credential on every /v1 request:
Authorization: Bearer ce_your_api_key_hereKeys belong to one organization and store only a one-way hash. The plaintext is displayed once. Keep keys in a server-side secret manager; never commit them or expose them in browser code.
Scopes
| Scope | Access |
|---|---|
data:read | Creators, brands, agencies, sponsorships, and videos |
exports:read | Export history, status, and downloads |
exports:write | Queue new exports |
operations:read | Operation status, results, and callback deliveries |
operations:write | Start sponsor detection, brand discovery, and lookalike operations |
mcp:use | Authenticate the Creator Eagle MCP server |
Invalid credentials return 401; a valid key without the required scope returns 403. Responses include x-request-id for support.