The same key authenticates the MCP server. Set it as a Bearer token in your
agent’s config (no OAuth, no separate credential). That’s the header the MCP authorization
spec uses, so most clients ask for it by default.
Keys and billing
Keys carry their mode in the prefix, so you always know which one you’re holding. Customer keys are alwaysvbsk_live_. Test keys are an internal Vibeset tool, and the portal refuses to issue
one to a customer account.
A key needs either a card on file or a live credit grant. Each call runs real analysis against the
licensed catalog, so it costs money to serve and is metered accordingly (see
Metering & pricing). If we sent you a credit code, redeeming it stands in
for the card while the grant lasts, and your account can hold two live keys until you add
one. See
Starting credits. Set a monthly spend cap in the portal if you want a hard ceiling
while you build.
Each key gets its own rate limit, 60 requests per minute by default. More keys means more
concurrency, which is why a credit-funded account is capped at two of them.