Docs menu

Get started

API keys

Every tool runs on your own UnGovr Open Data key, which is free.

Get a key

LexLint holds no keys: yours is passed through to the data API on your behalf. check_access answers without a key, so you can test the connection before you have one, and claim_trial_key answers without one because it mints one; the other six refuse until you do, and say where to get one.

There are three ways to get one:

  • /lexlint-key in a Claude Code session. It hands you a sign-in link for a free one, takes the key you paste back, and puts it where your next session will read it: on Claude Code that is the env block of your user settings file, chmod 600, and never a file that gets committed.
  • claim_trial_key from any agent, without leaving the session. It mints a 30-day trial key good for 50 requests and 10 jurisdictions over its whole life and returns it in the result, with no account, no sign-in and no email.
  • The page https://lexlint.io/trial in a browser. A key made with an account at https://www.ungovr.org/open-data/api-keys has no expiry.

Where the key goes

The key travels as the X-API-Key header on every request to mcp.lexlint.io, which passes it through to the UnGovr Open Data API on your behalf. It goes in X-API-Key and nowhere else: an Authorization: Bearer header is read as an OAuth access token, never as a key.

The plugin reads the value from UNGOVR_API_KEY at process start rather than holding a copy of its own, so the key is never written into the server registration, and a key exported into an already-running session is read by nothing.

What it meters

LexLint stores nothing unless you explicitly ask it to: your key is passed through to the UnGovr Open Data API on every call, and the upstream free tier (currently 50 requests per day) is the only meter. The one exception is upload_lint_run, covered in the tool reference: a run reaches the portal only when you upload it yourself from the CLI, after LexLint has shown you exactly what it contains and you have said yes, and it is then kept against your UnGovr account rather than against the stateless worker behind mcp.lexlint.io. Rate-limit and authentication errors come back from upstream unchanged.