API keys
All API requests require authentication using a Bearer token. Get your API key from the Developer Platform. Include your key in all requests:Connector branding
When users connect external services (Google Drive, Notion, OneDrive), they see a “Log in to Supermemory” prompt by default. You can replace this with your own app name by providing your own OAuth credentials. This works for Google Drive, Notion, and OneDrive. See the full setup in Customization.Scoped API keys
Scoped keys are restricted to one namespace (what v3/v4 called a container tag). They can only access documents and search within that namespace — use them to give a client, session, or tenant limited access without shipping your org master key. Pairs with namespaces for multi-tenant isolation. Allowed endpoints:/v3/documents, /v3/memories, /v4/memories, /v3/search, /v4/search, /v4/profile
Scoped keys cannot read billing, manage org settings, or mint further keys.
Create a scoped key
The scoped-key endpoint still takes the namespace in a field namedcontainerTag.
Parameters
Response
Disable a scoped key
Revoke with theid from creation. Subsequent requests get 401. Memories and namespaces are not deleted.