Authentication
Protected API operations require authentication. Operations explicitly documented as public, such as query-type discovery and public status-page reads, do not. Databuddy supports API keys for server-side integrations, session cookies for browser-based apps, and Databuddy account sign-in (OAuth) for MCP clients such as Claude and Claude Code.
API Key Authentication
Use your API key in the x-api-key header:
curl -H "x-api-key: dbdy_your_api_key_here" \
https://api.databuddy.cc/v1/query/websitesAlternatively, use Bearer token format:
curl -H "Authorization: Bearer dbdy_your_api_key_here" \
https://api.databuddy.cc/v1/query/websitesGetting an API Key
Agent Auth Discovery
AI agents can discover Databuddy authentication without scraping this page:
The MCP server accepts OAuth sign-in: clients that support MCP authorization with Client ID Metadata Documents, such as Claude and Claude Code, connect to https://api.databuddy.cc/v1/mcp without a key and the user approves access in Databuddy. See the MCP server docs. The REST API and other MCP clients, including Cursor and Windsurf, use scoped API keys sent with x-api-key or Authorization: Bearer.
API Key Scopes
Scopes control what actions an API key can perform:
Access Levels
API keys can have two access levels:
Global Access
Access all websites in your account or organization. Best for:
Website-Specific Access
Access only specified websites. Best for:
Session Cookie Authentication
Browser-based applications using the Databuddy dashboard session can authenticate automatically via cookies. This works when:
fetch('https://api.databuddy.cc/v1/query/websites', {
credentials: 'include'
})Choosing an Authentication Method
Authentication Errors
Example error response:
{
"success": false,
"error": "Authentication required",
"code": "AUTH_REQUIRED",
"requestId": "req_abc123def456"
}Best Practices
How is this guide?