# API Authentication & Usage Guidelines - Urva Gandhi Portfolio

> Guidelines for accessing public endpoints and MCP tools on Urva Gandhi's Portfolio.

## Free Tier (Self-Serve, No Signup)
The developer API and MCP server are free and open. To obtain a scoped API key without human contact, self-serve it at:
- **Issue a key:** POST /api/keys (or GET /api/keys) — returns `apiKey` and `sandboxKey`.
- **Authenticate (optional):** `Authorization: Bearer <apiKey>` or `X-API-Key: <apiKey>`.

## Access Policy
All public endpoints (`/api/leetcode`, `/api/codeforces`, `/api/codechef`, `/api/gfg`, `/api/hackerrank`, `/api/mcp`) are open-access. No API key required.

## Sandbox Test Environment
Try the API safely with clearly-labelled sample data (zero quota impact):
- **Sample payloads:** GET /api/sandbox?platform=leetcode
- **Echo / tool test:** POST /api/sandbox/echo with a raw JSON body.
- **Response header:** `X-Environment: sandbox` marks every sandbox reply.

## Rate Limiting
- Standard IP limit: 100 requests / min
- MCP Tool invocations: 60 calls / min
- Headers: `RateLimit-Limit`, `RateLimit-Remaining`, `RateLimit-Reset` (+ `Retry-After` on 429)
