Skip to content
THIRI logo
build.thiri.ai
Music theory for agents

Docs · Keys, tiers and limits

Keys, tiers and limits

A free account holds one active key; Developer accounts hold up to ten and a Licence up to 25, one per app or environment. Keys are shown once, can be rotated with a 24-hour overlap, and are revoked instantly.

Updated 2026-10-02

Getting a key

  1. Sign in at /keys with Google or a one-time email link.
  2. Create a key with an optional label (production, ci, my-laptop). Creating a key accepts the pre-release developer terms shown under the button.
  3. Copy it now. The full key is shown once. The keys page later shows only the prefix.

Tiers

FreeTheory ProDeveloperLicence
Calls a month1,00010,000100,0001,000,000
Calls a minute601203001,000
Active keys121025
PriceFree, no card$5 a month, founder rate locked for life until Dec 31, 2026$20 a month, founder rate locked for life until Dec 31, 2026$1,200 a year, commercial use of the MCP server. Get the licence
How to get itCreate a keySign in at /keys and pick a plan. Payment is by card through Stripe; the account's keys move to the new limits within a minute

Every tier is a hard cap: at the limit the API answers 429 quota_exceeded until the month resets on the first. Cancelling a plan drops the keys back to the free limits at once. Keys issued under the earlier Builder tier have the Developer limits.

T.H.I.R.I. Builders on Skool is the community: the Monday repo show, the Thursday call, the ship logs and the private repos. It does not change a key's tier.

Rate limits

  • Per key, per minute: 60 on free, 120 on Theory Pro, 300 on Developer, 1,000 on Licence. Exceeding it returns 429 rate_limited with a message naming the tier.
  • Per IP: an additional throttle protects the service from unauthenticated floods. Normal use never meets it.
  • Monthly quota: every successful /v2 call counts one. Failed calls (4xx) do not. Watch X-Quota-Used and X-Quota-Limit on each response.
429 when the monthly quota is spent
{
  "error": "quota_exceeded",
  "message": "Monthly quota of 1000 calls reached on the free tier. ..."
}

Rotate and revoke

Rotate when a key may have leaked or on a schedule. A new key is issued immediately and the old one keeps working for 24 hours so you can roll deployments. Revoke stops a key at once; anything using it fails with 401 from that moment. Both live on /keys.

rotation
# Rotate from the keys page (/keys) or, with a signed-in session,
# POST https://keys.thiri.ai/v2/keys/{id}/rotate
# The old key keeps working for 24 hours, then stops.

Handling the key safely

  • Store it in an environment variable or your client's config. Never in a repo, a screenshot or a shared prompt.
  • Browser apps: the key is visible to anyone who opens dev tools. Put a tiny proxy in front of the API for anything public, or ask for a scoped key.
  • On Developer or Licence, one key per app. If one leaks, you rotate one thing.
  • Anonymized usage (volumes, latency, error rates) is logged to run the service. Query bodies are logged to improve the engine's vocabulary; do not send secrets in chord names.

About sign-in

The keys page signs you in with a one-time email link. If the link does not arrive within a minute, check spam, then try again; if it keeps failing, email dennison@bluesprincemedia.com and we will sort it out by hand.

Next

Errors →

Every error code the API returns and what to do about it.