# OpenGrant authentication and permissions

## Public preview

The public REST API and MCP server require no account, API key or OAuth token. All public tools are read-only. Their scope is limited to matching grant counts and the same three example grants available to free visitors. No client may use these endpoints to read the paid directory.

## Paid web workspace

Subscribers sign in using an email link. The website sets a secure, HTTP-only session cookie for that account. A £29/month subscription unlocks complete grant search results, funder research and peer lookup in the web workspace. This session does not authorize a public API or MCP endpoint to access subscriber-only records. Delegated OAuth access and API keys are not currently offered.

See [pricing](https://opengrant.co.uk/pricing), [privacy](https://opengrant.co.uk/privacy), and the [developer guide](https://opengrant.co.uk/developers).
