# Guides

Ten short walks in plain words — from the key in your hand to the webhook at your door. Read them in order the first time; each stands alone after that.

- [Authentication and key hygiene](/guides/authentication-and-key-hygiene/) — Every call to the API carries a session token, and every session token comes from an API key.
- [Your first call](/guides/your-first-call/) — Five minutes from a key to your first page of records.
- [Paging and the cursor grammar](/guides/paging-and-the-cursor-grammar/) — Every listing answers a page, never the whole set.
- [Versions and the envelope](/guides/versions-and-the-envelope/) — Every request and every answer carries a small block under extensions.at: the envelope.
- [Errors and retries](/guides/errors-and-retries/) — A refusal is never a bare status code.
- [Rate limits](/guides/rate-limits/) — Calls are metered so the service stays responsive for everyone.
- [Dry runs](/guides/dry-runs/) — Some changes can be rehearsed: every check runs, the write is rehearsed against your current records, and nothing is stored.
- [Webhooks and the signature](/guides/webhooks-and-the-signature/) — A webhook subscription is your https endpoint, signed and POSTed when the events you picked happen — so your systems hear about a change the moment it happens instead of polling for it.
- [The agent channel](/guides/the-agent-channel/) — AI shopping agents can buy from your shop over the open UCP standard, and an agent channel is your set of controls for them.
- [Search](/guides/search/) — One word finds the records that carry it — every kind at once, grouped by kind, and only the kinds your key may read.

