Skip to main content
MCP requests must authenticate as a portal user. Agent bot tokens are not accepted on the MCP endpoints.

Access token

Send the user access token in the api_access_token header, the same header used by the Application API.
Get the token from GET /api/v1/profile or from the profile page in the portal.

OAuth bearer token

MCP clients can use OAuth 2.0. Send a Doorkeeper JWT as a bearer token:
Discovery: Supported scopes: profile, accounts, read, write. Unauthenticated requests return 401 with a WWW-Authenticate header that points at the protected-resource metadata.

Account membership

The account-scoped endpoint requires the authenticated user to be a member of {account_id}. Otherwise the server returns a forbidden MCP error. Tools are further filtered by the user’s account permissions. A caller only sees tools they are authorized to list and call.