Skip to content
Dashboard

Get started

FAQs

Send your Trace API key in the X-API-Key header on every request. See Authentication for the key classes and which endpoints each one reaches.

MCP uses OAuth through your Trace user account — there is no API key field for MCP clients. The client opens a browser sign-in on first connect and stores the token itself. See MCP setup.

In the Trace app under Settings → API Key. The full key is shown once and can’t be retrieved again, so store it before closing the dialog. Rotating issues a new key and invalidates the old one.

No. Treat a key like a password: keep it server-side, never commit it, and never ship it in a client bundle where anyone can read it.

Metered REST and MCP operations charge for net-new company records returned, with a re-access window for recently unlocked companies. Credits & usage has the full model.

Not within the re-access window — a company you’ve already unlocked is free to read again for 30 days. Only net-new companies draw down credits.

The API or MCP tool returns a structured insufficient-credit error instead of returning data. Nothing is charged and no partial result is returned.

Yes. Both draw on the same monthly allocation, so usage from an agent and from your own services counts against the same balance.

Trace re-crawls on a rolling schedule, and every technology carries first_seen and last_seen so you can judge freshness per signal rather than assuming a single site-wide age.

Fields with no data are omitted rather than returned as null, so a real response is often smaller than a documented example. Treat every field as optional.

Send it back to us through the data flags API and it goes into the review queue. Flagging a specific field is more actionable than flagging the company.

Yes — company endpoints accept either a domain or a Trace slug as the identifier. See the Companies API.

Structured JSON errors with a code or validation detail and a message that explains the failure. Errors lists the status codes and shapes.

Back off and retry after the indicated delay when a 429 is returned. Rate-limit headers on every response tell you how much budget is left before you hit one.

The interactive reference runs real requests in the browser. Without a key it shows sample responses; with one it hits your own data and meters normally.