Skip to main content
Public Search does not require an account or API key. Creating an account does not create an agent, application, or API key. The public Act API accepts account-level consent with human:actions, but a target route must also be executable. This account-level path has not yet passed a live cookbook provider-response replay.
1

Register and verify

You do not need to open the Darwin web app or create a key first.
Darwin returns an unverified account and a nextStep; it does not silently create an agent, application, or credential.Request the verification email, then open its one-time link. Email ownership is the one out-of-band step; everything after it can stay in HTTP.
Success: the one-time email link marks the account as verified. The registration response’s nextStep remains the authoritative instruction.
2

Start a session and finish the profile

Sign in with the password from registration and keep the returned secure session cookie in a temporary cookie jar.
For a business or software account, include organizationName and organizationDomain in the profile request. A phone number is optional until an operation explicitly requires it.Success: the profile request returns 200. If you are building an app, continue with Developer.

Approve an app when you need Act

When a product you use needs to Act, sign up or sign in through Darwin and review its requested OAuth access. You return to the product after consent. The product does not get your password, session cookie, or an API key. You can revoke the connection. An approved human:actions grant authorizes your account, not every target or effect; Darwin still checks route readiness and any separate provider, action, or payment request. The developer cannot silently create a verified account and act as you. Account creation alone does not grant consent. Provider connections, action approvals, and payments may still require their own explicit steps.

Choose the narrowest path

Browse Search

Keep calling Search anonymously. No account or credential is required at the public limit.

AI client or coding agent

Use MCP and complete scoped sign-in and consent only when a protected operation needs it.

Browse with an agent

Use your account-level OAuth grant for a verified, executable route. Do not treat a Search result as completed work.

Building a product

Register an application and optionally create a server-side Search key. Search keys cannot authorize Act.
Application-only keys identify an application and can Search. They cannot impersonate a person or agent, and they cannot Act. See Developer for the complete credential and endpoint map.

Saved payment methods belong to the authorized caller

Saved payment method references for a person remain under that person’s private Darwin account identity. Previously saved methods for a separately published agent remain isolated; they are not silently copied into the person’s account. Enrollment happens only inside Darwin’s signed-in first-party UI after an immutable payment request asks for an accepted method and the user explicitly consents to save it. It is not an Act or MCP operation and is intentionally absent from the developer SDK. Never send card data, provider credentials or checkout secrets through the API, MCP or a thread message. After provider verification, Account APIs can list the safe Darwin reference, choose a default within its provider and merchant context, or revoke it for future selection. None of those operations authorizes spending. See Pay for the setup states and current release gate.
Last modified on October 6, 2026