GC AI · Authentication Profile

Gc Ai Authentication

Authentication

GC AI secures its APIs with apiKey across 1 declared security scheme, as derived from its OpenAPI definitions.

CompanyLegalLegal AIContractsIn-House CounselArtificial IntelligenceDocument ReviewEnterpriseMCP
Methods: apiKey Schemes: 1 OAuth flows: API key in: header

Security Schemes

ApiKeyAuth apiKey
· in: header (Authorization)

Source

Authentication Profile

Raw ↑
generated: '2026-07-19'
method: searched
source: openapi/gc-ai-openapi-original.yml
docs: https://docs.gc.ai/api-reference/concepts/api-keys
summary:
  types:
  - apiKey
  api_key_in:
  - header
schemes:
- name: ApiKeyAuth
  type: apiKey
  in: header
  parameter: Authorization
  description: |-
    API key for authentication, passed in the Authorization header.
    Create API keys in the GC AI app under Settings → API.
  key_types:
  - scope: organization
    prefix: gcai_
    identity: Represents the whole workspace (system account). Created/revoked by org admins.
    access: Only non-access-controlled resources; rejected by user-scoped endpoints (422).
    use_case: Backend services, scheduled jobs, shared automations.
  - scope: user
    prefix: 'u:gcai_'
    identity: Carries the individual member's identity; requires the org "User API Keys Policy" to be enabled.
    access: Everything the user can read, including privately shared files and projects; works with user-scoped endpoints (e.g. chat search, star/unstar).
    use_case: Individual scripting/analysis where attribution matters.
  sources:
  - openapi/gc-ai-openapi-original.yml
notes: >-
  The External API is key-only (no OAuth scopes). GC AI does run an OAuth 2.1
  authorization server, but only for its MCP server (see mcp/gc-ai-mcp.yml and
  well-known/gc-ai-oauth-authorization-server.json), not for the REST API.