# Authentication

> Sign in on the web or from the CLI, create API keys, and use your own Gemini key. Which credential wins, and what logout does.

Page: https://scribiz.com/docs/authentication

Scribiz takes one credential per run. It is either a Scribiz credential (your account, counted in minutes) or a Gemini key of your own (direct to Google, billed by Google).

## Pick a credential

| You are | Use | Model calls go through | Counted in |
| --- | --- | --- | --- |
| Trying the web tool | Nothing | Scribiz | A small daily quota |
| A person with an account | Sign in | Scribiz | Your plan's minutes |
| Using the CLI with an account | `scribiz login` | Scribiz | Your plan's minutes |
| Using the CLI without an account | Your own Gemini key (`scribiz setup`) | Your machine, then Google | Google's bill |
| Writing code against the API | An API key | Scribiz | Your plan's minutes |
| Connecting an agent over MCP | None, an API key, or your account or your own Gemini key with `scribiz mcp` | Scribiz, or your machine | See [MCP connection modes](https://scribiz.com/docs/mcp/connection-modes.md) |

With your own Gemini key, the CLI fetches links and cuts audio on your machine and calls Google directly. Scribiz's own Google key stays on its servers. With a Scribiz sign-in, the CLI still fetches links and cuts audio on your machine, and sends the audio to Scribiz, which sends it to Google.

## Sign in on the web

Open `/login`. There is no password: you get an email link, and the page also offers Google when it is set up. A link works once and expires after 5 minutes. A signed-in browser session is only for the website. Code uses keys.

## Sign in from the CLI

```bash
scribiz login
```

The CLI shows a code and a link, and opens the link in a terminal. You confirm the code at `https://scribiz.com/login/device` while you are signed in to Scribiz. The CLI then saves a Scribiz key to `~/.scribiz/config.json`, readable by you only. This needs `scribiz` 0.1.1 or newer.

- The key counts in your plan's minutes. A free account has 30 minutes a month. `scribiz whoami` shows how many you have left.
- Your audio goes from your machine to Scribiz, which sends it to Google. With `--visual`, so does a low-resolution copy of the video.
- The key is listed in the dashboard under API keys, with `CLI on` and the name of your machine. Revoke it there.
- A code lasts 10 minutes. Without a terminal to open a browser, or on a server, make a key in the dashboard and set `SCRIBIZ_API_KEY`, or run `scribiz login --key` and paste it.
- When your minutes are used up, the CLI stops with exit code 3 and says when they come back. Your own Gemini key is the other way: run `scribiz setup`.

`scribiz logout` removes the saved key from this machine. It does not revoke it, because the CLI does not tell Scribiz. The key keeps working until you revoke it in the dashboard.

## API keys

Keys are created and revoked in the dashboard under API keys.

- A key looks like `sbz_live_` followed by random characters. Copy it when it is created. It is shown once.
- Scribiz stores only a hash of the key, so a lost key cannot be recovered. Create a new one and revoke the old one.
- Each key has a scope: `all`, `mcp` or `read`. `all` includes the others, and `mcp` includes `read`.
- You can have up to 10 keys. The dashboard shows when each was last used.
- A revoked key stops working within about a minute.
- A key cannot create or revoke keys. That needs a signed-in session, so it happens in the dashboard.

Send a key as a bearer token, or in an `X-API-Key` header:

```bash tab="Bearer"
curl https://scribiz.com/api/v1/me \
  -H "Authorization: Bearer $SCRIBIZ_API_KEY"
```

```bash tab="X-API-Key"
curl https://scribiz.com/api/v1/me \
  -H "X-API-Key: $SCRIBIZ_API_KEY"
```

[API authentication](https://scribiz.com/docs/api/authentication.md) covers scopes and rotation.

## Use your own Gemini key

This is the way to run the CLI without an account. With a Gemini key the CLI processes on your machine and calls Google directly. Scribiz minutes are not used, and Google bills you. Speech to text costs about $0.32 per hour of audio at today's prices, plus a fraction of a cent for the summary, and Google's free tier may cover light use. Get a key at [Google AI Studio](https://aistudio.google.com/apikey).

```bash
export GEMINI_API_KEY=your_gemini_key_here
scribiz ./interview.mp4
```

Or run `scribiz setup` and paste the key once. It checks that the key works before saving it to `~/.scribiz/config.json`, readable by you only. Without a terminal, pipe the key in: `echo "$KEY" | scribiz setup`. A Scribiz key does not go here: `setup` refuses a key that starts with `sbz_` before it contacts Google, and points you to `scribiz login --key`.

> [!WARNING]
> Google may use content sent with a free-tier Gemini key to improve its products. Turn on billing for the key to opt out.

The key is sent to Google and nowhere else. It never goes to Scribiz servers.

## Which credential wins

For the CLI, the first match in this list is used:

1. `SCRIBIZ_API_KEY` in the environment.
2. `GEMINI_API_KEY` in the environment.
3. The config file: a saved Scribiz key, then a Gemini key from `scribiz setup`.

The config file holds one credential at a time. `scribiz login` and `scribiz setup` replace each other: signing in removes a saved Gemini key, and saving a Gemini key removes a saved sign-in. Environment variables are not touched, so a `GEMINI_API_KEY` that is still set keeps a run on your own key after you sign in. Run `scribiz whoami` to see which one a run will use: it says when `GEMINI_API_KEY` is overriding a saved sign-in. `--no-config` ignores the config file. [Config and env](https://scribiz.com/docs/cli/config.md) lists every variable.

`scribiz logout` removes what the file holds. It never revokes a Scribiz key, and it leaves your environment alone.

## Sessions are not keys

The website uses a cookie session. The CLI never keeps a session: when you sign in from the command line, the approval is swapped for an API key, which you can see and revoke in the dashboard. Code uses an API key.

---

Checked against the Scribiz build on 2026-10-05.
