CueFrame API authentication and policies
Last updated October 7, 2026
Authentication and least privilege
CueFrame uses OAuth authorization code with PKCE S256 for hosted MCP and accepts API keys for automation. Discover the existing issuer at authorization server metadata and the MCP resource at protected resource metadata. The issuer is https://api.cueframe.ai.
Request explicit resource scopes such as projects:read and media:read for least privilege. Read and write are separate grants; write does not imply read. Supported resources are media, sessions, projects, renders, webhooks, and billing. Existing identity-only OAuth grants retain account-level access. API keys use the equivalent resource/action permissions selected at creation. See the OpenAPI specification for each operation.
Rate limits
Authenticated REST responses subject to the customer limiter include RateLimit-Policy and RateLimit fields following draft-ietf-httpapi-ratelimit-headers-11, an IETF work in progress rather than a published RFC. The q parameter is quota, w is its period in seconds, and r is observed remaining capacity. The shared global limiter reports one shard conservatively, not an aggregate guarantee. Read requests check capacity without consuming it; writes consume tokens. Internal platform traffic is exempt. Public discovery is not assigned an invented customer quota.
A 429 response includes Retry-After in seconds. Wait at least that delay before retrying, use jitter, and reuse an idempotency key where supported. Available quota can change with concurrent requests and token refill; it does not guarantee a later request will succeed.
Versioning and deprecation
REST operations use the /v1 URL prefix. Additive fields may appear within a version; clients should tolerate unknown response fields. Breaking changes require a new API version. Planned removal of an endpoint will be announced in the CueFrame changelog and its documentation, with migration instructions. A deprecated response will use the Deprecation structured date header; when a removal date is established it will also include Sunset as an HTTP date and a Link with rel="deprecation" to the migration notice. Active endpoints do not carry fabricated retirement dates.
Self-serve onboarding
Start in the CueFrame app to create an account and API keys. The current offer includes $20 in free cloud credits with no card required; see pricing. Key prefixes distinguish cf_live_ and cf_test_ credentials, but a prefix alone does not guarantee a free or isolated sandbox. Confirm the environment and pricing before starting paid work.
The public Streamable HTTP endpoint at https://api.cueframe.ai/v1/mcp/x402 allows initialize and tools/list without credentials. Tool execution that accesses data or paid services requires payment. The authenticated endpoint at https://api.cueframe.ai/v1/mcp uses OAuth or a bearer key. See setup instructions.