Episode 10: Research APIs, a ladder of keys
Have your AI agent fetch research data from an API, one rung of keys at a time: OpenAlex with no key, a free key you limit (a reference library checked for retractions), and a paid key (ElevenLabs narration, estimated first). Where a key can go in Claude Code, Codex and Antigravity, what 401, 403 and 429 mean, and the license that comes with the data.

Downloads
AI for Research Efficiency, episode 10, with Douglas Hutchings. Narration: an AI-generated voice (ElevenLabs).
An API is a door for programs: you ask with a web address, and the answer comes back as data. This episode climbs a ladder of keys with a real example on each rung: OpenAlex with no key, a free key you limit, and a paid key, estimated first. Every figure was read on 4 October 2026; the services change their limits and prices often, so check each one's own page (Sources, below) before you rely on it.
1. An API is a door for programs
A request is a web address. This one asks OpenAlex for the University of Arkansas's works, grouped by year:
https://api.openalex.org/ works? filter= institutions.id:I78715868, publication_year:2016-2025& group_by= publication_yearThe answer is JSON. OpenAlex also says what each answer cost, in the answer (meta.cost_usd) and in its headers (x-ratelimit-cost-usd, and what is left today in x-ratelimit-remaining-usd). On 4 October 2026 this request cost $0.0001 and returned 25,613 works for 2016 to 2025.
2. No key: OpenAlex
- OpenAlex's data is released under CC0: free to reuse for anything.
- Ask your agent to read the documentation first (help.openalex.org). Names are ambiguous, so it should find the ID first: the University of Arkansas (Fayetteville) is
I78715868in OpenAlex, ROR05jbt9m15. Other campuses of the University of Arkansas System have their own IDs. - Without a key you get $0.10 of use a day: about 1,000 list requests like the one above. A free key (an OpenAlex account) gives $1 a day, ten times as much. Looking up one work by its DOI is free.
- The old "polite pool" (adding your email address to each request) was replaced by API keys in February 2026; the
mailtoparameter is now ignored. Agents trained before then may still add it, or call it optional.
Try it in your agent:
Using OpenAlex, how many works did my university publish each year from 2016 to 2025? Read OpenAlex's documentation first, look up the university's ID, and show me every URL you call.3. A free key you limit
Your reference library is private, so Zotero's API needs a key to read it. When you make one in your zotero.org account's settings, allow read access to your library only: no notes, no write access, no groups.
- Put the key in a
.envfile in your project folder:ZOTERO_API_KEY=... - Add
.envto.gitignore, so it never goes into a repository. - Tell the agent the variable's name, never the value: "Use the key in ZOTERO_API_KEY. Never print it."
- When the work is done, delete the key on zotero.org.
Some guides (OpenAlex's own, for chat assistants) suggest pasting a key into the chat. Don't: the chat is stored, and your OpenAlex key is also your sign-in.
Is anything in my library retracted? In the film, the library is a list of DOIs exported to a file (library.csv), and the agent checks each one against OpenAlex (one lookup per DOI, free). OpenAlex flags a work as retracted from the Retraction Watch database. Open the retraction notice and confirm it yourself.
Is anything in my library retracted? library.csv lists my references by DOI. Check each DOI against OpenAlex (single lookups are free), write retractions.csv with an is_retracted column, and show me every URL you call.4. Where a key can go
| Claude Code | Codex | Antigravity CLI | |
|---|---|---|---|
Keep the agent from reading .env | a deny rule in .claude/settings.json: "deny": ["Read(./.env)"] (in our test it also stopped the agent's own cat .env) | no setting for this | the sandbox blocks .env files, but it is off by default in the CLI: turn it on with agy --sandbox or "enableTerminalSandbox": true |
| Can a script the agent runs read the key? | yes: in our test, a script it ran read the key's length from .env | yes | not inside the sandbox |
| Variables passed to the commands it runs | [shell_environment_policy]: by default names with KEY, SECRET or TOKEN are not removed (ignore_default_excludes = true) |
So, in all three: the key stays in the .env file, the agent gets its name, and you read what a script prints before you share its output.
Our Codex tests (Codex 0.160.0 on a Linux server, 4 October 2026, with a demo key): run as codex exec, a script reported that both a KEY-named variable and an ordinary one reached the command, as the documented default says. In the interactive session, neither did: Codex ran the commands through its background app server, started the day before with its own environment. Either way, a key in your environment can reach what an agent runs; keep it in .env and give the agent its name.
5. A key that spends: estimate first
ElevenLabs turns text into speech. It is paid, and it is the voice service this series is narrated with (we use it and value it).
- Estimate before the request. The summary in the film is 401 characters; at the rate this series' account was charged on 4 October 2026 (about 0.11 credits a character), about 45 credits. It cost 44. That rate was ElevenLabs' launch price for its v4 model, which ran until 12 October 2026; after it, expect roughly three to four times as many credits a character. Read your plan's current rate on elevenlabs.io before you estimate.
- A key for this job only: when you create it (elevenlabs.io, API keys), restrict it to Text to Speech and set a credit quota. Keys can also be limited to IP addresses and given an expiry.
- The request names the key's variable, never the value:
curl -X POST "https://api.elevenlabs.io/ v1/ text-to-speech/ $VOICE_ID" \ -H "xi-api-key: $ELEVENLABS_API_KEY" \ -H "Content-Type: application/ json" \ -d @summary.json -o summary.mp3- Listen before you use it.
- The license: ElevenLabs' free plan is for non-commercial use only, and anything you publish from it must carry "elevenlabs.io" or "11.ai" in its title. All paid plans include a commercial license (unless you use its beta services).
The summary read in the film: "Draining rice paddies now and then, instead of keeping them flooded, cuts methane. A 2025 review of eleven meta-analyses found that methane fell by thirty-one to sixty-two percent, while nitrous oxide rose. Yields changed little on average, and mild drainage, timed to the crop, can even raise them. The author's advice: fit the schedule to local conditions, and use better yields to win farmers over." From Minamikawa (2025), Paddy and Water Environment, CC BY 4.0.
6. Manners: limits and licenses
| Status | Means | Do |
|---|---|---|
| 401 Unauthorized | no key, or a key it does not accept | check the key's variable |
| 403 Forbidden | the key is known but has no right to this | check the key's scope |
| 429 Too Many Requests | too many requests, or today's allowance is spent | wait (the Retry-After header says how long), then go slower |
Research APIs: keys, limits and licenses (read 4 October 2026)
| API | Key | Limits | License of the data |
|---|---|---|---|
| OpenAlex | none to try; a free key for 10 times the daily allowance | $0.10 a day without a key, $1 with a free key; at most 100 requests a second | CC0 |
| ROR (research organizations) | none | 2,000 requests per 5 minutes per IP address | CC0 |
| Crossref | none; your email (mailto) for the polite pool | lists: 1 request a second (3 with your email) since 21 July 2026 | metadata facts CC0; abstracts excepted |
| PubMed E-utilities | optional (an NCBI account) | 3 requests a second without a key | NCBI's notices; abstracts may be copyrighted |
| arXiv | none | one request every 3 seconds, one connection | metadata CC0; e-prints need their authors' permission |
| Zotero | a key for a private library | back off when asked (Backoff, Retry-After) | your own data |
| Unpaywall | your email | 100,000 calls a day; search retired 18 September 2026 (use OpenAlex) | |
| Semantic Scholar | optional, on request | 1,000 requests a second, shared by all keyless users | attribution required; some data CC BY-NC |
| ORCID public API | none or free credentials | not for any revenue-generating product or service | |
| Lens | after approval | a trial for non-commercial or limited academic use | |
| USPTO Open Data Portal | a USPTO.gov account with multi-factor sign-in and a validated ID.me account; one key per person | ||
| Google Scholar | no API | automated access disallowed (robots.txt) | |
| ElevenLabs | yes (scope, credit quota, expiry) | by plan | commercial use on paid plans |
Data under a non-commercial license (Semantic Scholar's CC BY-NC data, ORCID's public API, Lens' trial) is fine for your own research; it stays out of anything you sell or monetize.
Not confirmed yet: whether a variable set before an interactive codex session starts reaches its commands on a Windows PC (on our server it did not; under codex exec it did); Antigravity's sandbox on Windows (its app documents it as a preview).
Try it
Before you use an agent for university work, check your campus's rules for AI tools (episode 9): the University of Arkansas's AI guidelines, for example, ask that any AI tool used on a university system or for university business be vetted and approved by its IT services (UITS) first. OpenAlex's data is public; your own data is another matter.
- Ask your agent for your campus's works per year from OpenAlex.
- No key needed.
- Open the web address it used in your browser: you should see the same numbers, as JSON.
Sources
Read on 4 October 2026 (copies kept with the project). The agents' screens come from sessions recorded that day in Claude Code 2.1.289 and Codex 0.160.0, in folders outside the studio's repository; the OpenAlex and Crossref answers from requests made that day without a key.
- OpenAlex: Authentication (opens in a new tab); Example costs (opens in a new tab); Pricing (opens in a new tab); Deprecations (opens in a new tab); Using OpenAlex with an AI assistant (opens in a new tab); Work attributes (opens in a new tab); LLM quick reference (opens in a new tab).
- Zotero: Web API basics (opens in a new tab); Key permissions (opens in a new tab).
- ElevenLabs: API keys (opens in a new tab); Create speech (opens in a new tab); Can I publish the content I generate? (opens in a new tab); Pricing (opens in a new tab).
- The agents: Claude Code: permissions (opens in a new tab); Codex: advanced configuration (opens in a new tab); Antigravity: terminal sandbox (opens in a new tab).
- Status codes: MDN Web Docs, 401 (opens in a new tab), 403 (opens in a new tab), 429 (opens in a new tab), Retry-After (opens in a new tab).
- The APIs table: ROR (opens in a new tab); Crossref access (opens in a new tab) and its 2026 limits (opens in a new tab); NCBI policies (opens in a new tab); arXiv API terms (opens in a new tab); Unpaywall API (opens in a new tab); Semantic Scholar license (opens in a new tab); ORCID public API terms (opens in a new tab); Lens API (opens in a new tab); USPTO Open Data Portal (opens in a new tab); Google Scholar help (opens in a new tab).
- The paper summarized: Minamikawa, K. (2025). Climate-smart water management in rice paddies: a meta-synthesis on greenhouse gas emissions and yield impacts (opens in a new tab). Paddy and Water Environment 23:525–532. CC BY 4.0.
- The retraction: the 1998 Lancet paper (10.1016/S0140-6736(97)11096-0 (opens in a new tab)), retracted 6 February 2010 (Crossref's record, from Retraction Watch).
Corrections
None so far. If you find something wrong, email doug,@douglashutchings.com.
Transcript
Every spoken line, by chapter
Research APIs
How much does the University of Arkansas publish each year? Ask your agent, and it asks OpenAlex.
25,613 works in ten years, counted by one web address. No key, and the answer even says what it cost: a hundredth of a cent.
AI for Research Efficiency. Episode 10: Research APIs, a ladder of keys.
Last time: what never goes to an agent, and why keys live in a .env file.
In this episode: three research services, and the three kinds of key they take: none, a free key you limit, and a key that spends money.
1. A door for programs
One: an API is a door for programs.
You ask with a web address, and the answer comes back as JSON: plain text that a program can read.
OpenAlex adds what each answer cost, and how much of today's allowance is left.
2. No key: OpenAlex
Two: no key at all.
OpenAlex catalogs the world's research: works, authors, institutions. Its data is free to reuse, for anything.
Ask the agent to read the documentation first. Names are ambiguous, so it finds the university's ID before it counts.
One request groups ten years of works by year. It's only a web address: open it in a browser, and the numbers are the same.
Without a key, you get ten cents of use a day: about 1,000 of these requests. A free key gives you ten times that.
3. A free key you limit
Three: a free key you limit.
Your reference library is private. Zotero's API needs a key to read it, and you choose what the key may do: read, and nothing else.
The key goes in the .env file, never into the chat, even where a guide suggests it. The agent gets only the variable's name.
Then ask: is anything in my library retracted? Here the library is exported as a list of DOIs, and the agent checks each one against OpenAlex. Single lookups are free.
One comes back retracted, a flag OpenAlex takes from the Retraction Watch database. Open the notice, and confirm it yourself.
Notice the agent's note, too: it calls OpenAlex's email lane optional. That lane closed in February, which is why you ask an agent to read the current documentation.
When the work is done, delete the key.
4. Where a key can go
Four: where a key can go.
Claude Code can be told never to read the .env file, and here it refused. But a script it ran could still read the key.
Codex has a setting for which variables reach its commands, and by default it doesn't remove names with KEY, SECRET or TOKEN in them.
Antigravity's sandbox blocks .env files, but in its command line, the sandbox is off until you turn it on.
So in all three: the key stays in the file, the agent gets its name, and you read what a script prints.
5. A key that spends: estimate first
Five: a key that spends money.
ElevenLabs turns text into speech. It's paid, and it's the service that narrates this series.
Before a paid request, estimate. This summary of the practice folder's paper is 401 characters: about 45 credits.
Make a key for this job only: text to speech, with a credit limit. The request names the key's variable, and the key itself never appears.
Then listen before you use it.
Draining rice paddies now and then, instead of keeping them flooded, cuts methane.
And check the license: ElevenLabs' free plan is for non-commercial use, with its name in the title. Paid plans include a commercial license.
6. Manners: limits and licenses
Six: manners.
401 or 403 means no key, or the wrong one. 429 means too many requests: wait, and try again, more slowly.
And data comes with a license. OpenAlex's is free for any use; some services allow only non-commercial use, and Google Scholar has no API at all. The companion page lists them.
Try it
Pause here, and try one: ask your agent for your campus's works per year from OpenAlex. No key needed. Then open the address it used.
Review and next
So: no key, a key you limit, a key that spends. Each key in the .env file, each paid request estimated, each answer checked.
Next: Map a research field with OpenAlex.
