# auth.md

Metals-API authenticates AI agents and API clients with an **API key**.

## Audience

Agents connecting to:

- REST API: `https://metals-api.com/api/*`
- MCP: `https://metals-api.mcp.metals-api.com/mcp`

## Registration

1. Create an account: [https://metals-api.com/register](https://metals-api.com/register)
2. Copy your access key from the dashboard
3. REST: pass `?access_key=YOUR_ACCESS_KEY`. MCP: pass `api_key` on each tool call. Do not put the key in the MCP URL — Claude Desktop and claude.ai reject tokens in the query string.

## Methods

| Method | How |
|--------|-----|
| REST query | `https://metals-api.com/api/latest?access_key=<key>` |
| MCP tool argument | `api_key` on each tool call (`https://metals-api.mcp.metals-api.com/mcp` — no key in the URL) |

## Discovery

- OAuth Protected Resource: `/.well-known/oauth-protected-resource`
- Authorization Server metadata: `/.well-known/oauth-authorization-server`
- MCP Server Card: `/.well-known/mcp/server-card.json`
- Docs: [https://metals-api.com/mcp](https://metals-api.com/mcp)
