Authentication
Protected API operations require authentication. Operations explicitly documented as public, such as query-type discovery and public status-page reads, do not. Databuddy supports API keys for server-side integrations, session cookies for browser-based apps, and Databuddy account sign-in (OAuth) for MCP clients such as Claude and Claude Code.
API key authentication
Use your API key in the x-api-key header:
curl -H "x-api-key: dbdy_your_api_key_here" \
https://api.databuddy.cc/v1/query/websitesAlternatively, use Bearer token format:
curl -H "Authorization: Bearer dbdy_your_api_key_here" \
https://api.databuddy.cc/v1/query/websitesGetting an API key
Agent auth discovery
AI agents can discover Databuddy authentication without scraping this page:
The MCP server accepts OAuth sign-in: clients that support MCP authorization with Client ID Metadata Documents, such as Claude and Claude Code, connect to https://api.databuddy.cc/v1/mcp without a key and the user approves access in Databuddy. See the MCP server docs. The REST API and other MCP clients, including Cursor and Windsurf, use scoped API keys sent with x-api-key or Authorization: Bearer.
API key scopes
Scopes control what actions an API key can perform:
Access levels
API keys can have two access levels:
Global access
Access all websites in your account or organization. Best for:
Website-specific access
Access only specified websites. Best for:
Session cookie authentication
Browser-based applications using the Databuddy dashboard session can authenticate automatically via cookies. This works when:
fetch('https://api.databuddy.cc/v1/query/websites', {
credentials: 'include'
})Choosing an authentication method
Authentication errors
Example error response:
{
"success": false,
"error": "Authentication required",
"code": "AUTH_REQUIRED",
"requestId": "req_abc123def456"
}Best practices
How is this guide?