Authentication Overview
The Metaculus API uses token-based authentication for all API requests. You must include a valid API token in theAuthorization header of every request.
Getting Your API Token
To obtain your API token:- Log in to your Metaculus account
- Navigate to your Account Settings
- Scroll to the “API Access” section
- Click to generate a new token or view your existing token
Token Format
API tokens are 40-character hexadecimal strings, for example:Making Authenticated Requests
Include your token in theAuthorization header with the Token prefix:
Token (literal string) + single space + your API token.
Example Requests
Authentication Errors
Common authentication error responses:401 Unauthorized - Missing Token
Authorization header in your request.
401 Unauthorized - Invalid Token
403 Forbidden
Token Security Best Practices
Use Environment Variables
Never hardcode tokens in your source code. Use environment variables instead:Rotate Tokens Regularly
For production applications, consider rotating your API tokens periodically:- Generate a new token from your account settings
- Update your application to use the new token
- Revoke the old token once migration is complete
Limit Token Exposure
- Don’t log tokens in application logs
- Don’t commit tokens to version control (.env files should be in .gitignore)
- Don’t share tokens in public channels or forums
- Use separate tokens for different applications or environments
Token Usage for Bots
API tokens are the recommended authentication method for automated bots and integrations. Session-based authentication is primarily for web users.
- Generate a dedicated API token for your bot
- Consider creating a separate Metaculus account for your bot
- Clearly indicate in your bot’s profile that it’s automated
- Respect rate limits to avoid disrupting the service
