Get started

Authentication

Authenticate API requests with a bearer API key, and MCP clients with Thrive sign-in.

API keys

Send your key in the Authorization header on every request. Keys start with thrive_live_.

http
GET /api/public/v1/me
Authorization: Bearer thrive_live_…

Scopes

Each key is limited to the scopes chosen when it was created. Scopes are checked on the server for every request.

New keys start with only markets:read. Add more only when you need them — viewing a portfolio never allows trading, and viewing projects never allows editing. No scope can change billing, credits, subscriptions, sign-in or security settings.

profile:readread

Read the key owner's id and display name.

markets:readread

Live quotes and daily price history. Cannot: Touch any portfolio or place trades.

simulations:readread

List Thrive's simulation catalog.

portfolio:readread

View virtual cash, positions and value. Cannot: Place trades.

trading:readread

View virtual transaction history. Cannot: Place trades.

trading:writewrite

Buy or sell in the owner's VIRTUAL practice portfolio (no real money). Cannot: Set cash, quantities or cost basis directly.

projects:readread

Read the owner's Agent Projects.

projects:writewrite

Create new Agent Projects.

progress:readread

Lesson and simulation completion counts.

agent:readread

List the owner's saved Agent chat titles.

agent:writewrite

Ask the Thrive Agent a question. Uses Agent credits.

connections:readread

See which outside apps are connected. Cannot: Read any data from those apps.

usage:readread

View credit balance and recent usage. Cannot: Change credits, billing or plans.

How keys are stored

  • Only a SHA-256 hash is stored. The full key is shown once, at creation.
  • Revoked or expired keys stop working immediately. Keys can have an optional expiry date.
  • Every request records a last-used time and appears on Usage.
  • A key can only ever read its owner's data.

MCP authentication

MCP clients can authenticate two ways. Recommended: an MCP connection key from MCP Connections, sent as Authorization: Bearer thrive_live_…. It uses exactly the same scopes, rate limits, idempotency and audit log as the API, and the client only sees tools its scopes allow. Alternatively, clients like Claude and ChatGPT can sign in with your Thrive account (OAuth) to use the notes, alerts and saved-items tools.

Never put an API key in browser code, public repos or URLs. Call Thrive from your server.