Access token
Send the user access token in theapi_access_token header, the same header used by the Application API.
GET /api/v1/profile or from the profile page in the portal.
OAuth bearer token
MCP clients can use OAuth 2.0. Send a Doorkeeper JWT as a bearer token:
Supported scopes:
profile, accounts, read, write.
Unauthenticated requests return 401 with a WWW-Authenticate header that points at the protected-resource metadata.
Account membership
The account-scoped endpoint requires the authenticated user to be a member of{account_id}. Otherwise the server returns a forbidden MCP error.
Tools are further filtered by the user’s account permissions. A caller only sees tools they are authorized to list and call.