Updated October 6, 2026

Authentication and keys

Keys come with a plan. One key per request, in either header. Keys start with gds_.

Get a key

Keys come with a plan. In this order:

  • Create an account in the console, or sign in with your Gloom account, and confirm your email.
  • Choose a plan under Billing. Checkout runs on Stripe, and the plan starts once Stripe confirms the payment.
  • Create a key under Keys. It is shown once, so copy it then: Gloom stores only a hash and cannot show it again. A lost key is revoked and replaced.

Without a plan, creating a key is refused with 402.

Send the key

Either header works. When both are sent, Authorization is read first.

bash
curl https://api.gloom.sh/v1/macro/cpi -H "Authorization: Bearer gds_..."
curl https://api.gloom.sh/v1/macro/cpi -H "x-api-key: gds_..."

Keep keys on a server or in a script, never in a web page.

Key format

Gloom Datasets keys start with gds_. The Gloom API answers on the same host, but its keys are different keys for different APIs: a Gloom Pro key (gloom_mcp_) or News API key (gloom_news_) gets 401 wrong_key on a dataset route, and a gds_ key is refused with 401 on the Gloom API's routes. Anything else gets 401 invalid_key.

What a key reads

A key carries its account's plan. Keys have no scopes of their own: every key on an account reads the same datasets and spends from the same credits.

  • The account needs a plan. Without one, for example after a plan ends, every key gets 402 plan_required.
  • The account needs a verified email. Until then its keys get 403 key_disabled.
  • A revoked key gets 401 invalid_key.
  • How many keys an account holds depends on the plan:
Plan

Basic

Keys

5

Credits a month

150,000

Credits a minute

300

Plan

Desk

Keys

20

Credits a month

1,000,000

Credits a minute

1,200

Plan

Enterprise

Keys

by contract

Credits a month

by contract

Credits a minute

by contract

Until its contract sets them, an Enterprise account holds up to 100 keys at 6,000 credits a minute each.

Without a plan an account holds no keys and no credits, and any key it still has gets 402 plan_required.