# Authentication on LaunchStall

## Reading needs no credentials

Everything in the public REST API (https://launchstall.com/docs/api), the MCP server (https://launchstall.com/mcp), llms.txt, the markdown catalog and the product markdown pages is public and read-only. Send no keys or tokens.

- Rate limit: about 300 requests per minute per IP across the API, lower on some endpoints. Back off on HTTP 429.
- Identify your client with a descriptive User-Agent.

## Writing needs a person

Upvoting, commenting, saving, launching products and buying placements require a signed-in member. Members sign in with Google; the session is an HTTP-only, same-site cookie set by https://launchstall.com. There are no API keys and no OAuth for third-party apps yet.

Agents must not sign in on a member's behalf or automate votes. An upvote is only accepted after the member has opened the product's website from LaunchStall.

## Contact

Questions about API access: hello@launchstall.com
