# Getting started

> Create an account API key and send your first request.

## 1. Create an account

Sign up and sign in at [account.gujo.ai](https://account.gujo.ai). A key only sees the entitlements and subscriptions of that account.

## 2. Create an API key

Create a key in the **API keys** card of [account.gujo.ai/settings/developer](https://account.gujo.ai/settings/developer) (the **Developer settings** page of your account).

1. Enter a name. Anything that tells you which device or tool uses the key will do.
2. Pick abilities. `products.read`, `mcp.read` and `device.install` are selected to start with, which is enough to read your library and connect MCP. Add `orders.read` or `subscriptions.read` to read orders or subscriptions too.
3. Set an expiry date if you want one. Leave it empty and the key works until you revoke it.
4. Click **Issue key**. The key is shown only this once, so move it to a secret store or an environment variable right away.

What each ability means, the key limit and revocation are in [Authentication and API keys](auth.md).

```bash
export GUJO_API_KEY="the key you were given"
```

Don't put the key in command arguments or URLs. Both end up in shell history and server logs.

## 3. Send your first request

Fetch the products this key can use.

```bash
curl https://api.gujo.ai/api/library \
  -H "Authorization: Bearer $GUJO_API_KEY"
```

On success you get 200 and the products you can use, identified by numeric id, each with its delivery details and setup progress. The response shape is under `library` in the [API reference](api-reference.md).

On failure the body looks like `{"message": "...", "error": "<code>"}`.

| Status | `error` | Check |
|---|---|---|
| 401 | `missing_api_key` | The `Authorization` header is missing |
| 401 | `invalid_api_key` | The key is wrong, revoked or expired |
| 403 | `missing_api_key_ability` | The key lacks the `products.read` ability |

## 4. Connect an agent

An agent can do the same work over MCP. The endpoint is `https://api.gujo.ai/api/mcp`. Clients such as Claude Code and Cursor need no key: give them the URL and sign in through the browser. Where nobody can sign in, such as CI, use this key with the `mcp.read` ability. Install buttons and configs for each client are in [Connect MCP](mcp/index.md).

## Next

- To install a product you bought from a terminal, see [gujoctl](gujoctl.md).
- Every endpoint you can call is in the [API reference](api-reference.md).
