OAuth or API key? Connecting AI tools to ScanToPitch securely
The two ways to authenticate an AI assistant to ScanToPitch over MCP, one-click OAuth and API keys, and how to choose the safer fit.
When you connect an AI assistant to ScanToPitch, you prove who you are one of two ways: a one-click OAuth flow or an API key. Both are secure; they trade off convenience against control. Here is the difference in practical terms.
OAuth: the click-to-connect path
OAuth is the 'Sign in with…' experience you know from the web. You click connect in your assistant, land on a ScanToPitch consent screen, approve, and you are done. No secret to copy or store. The assistant receives a scoped token tied to your account. It is the easiest path and the right default for most people.
API keys: the portable secret
An API key is a string you generate on your account page and paste into a tool's settings. It works anywhere, in an assistant, a script, a server, which makes it flexible. The trade-off is that it is a secret you now hold: keep it out of shared documents and code repositories, and revoke it if a device is lost.
Which to use
If you are connecting a personal assistant like ChatGPT or Claude, use OAuth, it is faster and there is no key to leak. If you are wiring up a script, an automation platform, or a shared back-end, use an API key, that is what it is for. Some people use OAuth for their chat and a separate key for their automations, so the two can be revoked independently.
Good habits either way
Create a separate key per integration so you can revoke one without breaking the others. Review your active keys occasionally on the account page. And remember that whichever method you use, purchases stay human-only, no token, OAuth or key, can buy credits on your behalf.
Find your next client this week
Scan a city, see which local businesses have weak websites, and send a pitch that references the real problem.
Join the waitlist →