Obtain a Software/Integrator API key by registering as a vendor with Metrc.
Have each licensee generate a User API key inside their own Metrc account and share it with you.
Concatenate the software key and user key as "softwareKey:userKey" and Base64-encode the result.
Send the encoded value in an Authorization: Basic header on every HTTPS request.
Set Content-Type: application/json on POST and PUT requests.
Target the correct state-specific subdomain, since keys are not portable across states.
Known gotchas
The integrator key carries no permissions by itself; access is governed entirely by the user API key holder's permissions in Metrc.
Metrc is rolling out a v2 API and sunsetting v1 on a rolling, state-by-state schedule, so confirm which version and cutover date applies to your state.
API keys and hostnames are state-specific; a key issued for one state's subdomain will not work on another.
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?