# Concepts

How keys, sign-in, limits, errors, credits, sources and versioning work.

- [Authentication](https://fundalyze.ai/developers/md/concepts/authentication): API keys and connected apps (OAuth sign-in), what each is for, how to send them and where to revoke them.
- [Limits and quotas](https://fundalyze.ai/developers/md/concepts/limits): Daily calls per key, keys per account, one call at a time, the X-Quota-Remaining header and what a 429 means.
- [Errors](https://fundalyze.ai/developers/md/concepts/errors): Every status the API returns, the JSON shape of an error, how MCP reports the same failures and when to retry.
- [Credits](https://fundalyze.ai/developers/md/concepts/credits): How Fundalyze credits work, what spends them, and why nothing is blocked by them today.
- [Data sources and attribution](https://fundalyze.ai/developers/md/concepts/data-sources): Where every figure comes from, which sources are left out, and how to credit the data when you show it to others.
- [Changes and versioning](https://fundalyze.ai/developers/md/concepts/versioning): What can change in the API without notice, what counts as a breaking change, and where changes are announced.
