> ## Documentation Index
> Fetch the complete documentation index at: https://api-docs.rookoo.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate to the Rookoo portal MCP server with an access token or OAuth bearer token.

MCP requests must authenticate as a portal user. Agent bot tokens are not accepted on the MCP endpoints.

## Access token

Send the user access token in the `api_access_token` header, the same header used by the Application API.

```bash theme={null}
curl -X POST https://app.rookoo.ai/api/v1/accounts/1/mcp \
  -H "api_access_token: YOUR_ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/list",
    "params": {}
  }'
```

Get the token from `GET /api/v1/profile` or from the profile page in the portal.

## OAuth bearer token

MCP clients can use OAuth 2.0. Send a Doorkeeper JWT as a bearer token:

```bash theme={null}
curl -X POST https://app.rookoo.ai/api/v1/accounts/1/mcp \
  -H "Authorization: Bearer YOUR_JWT" \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "id": 1,
    "method": "initialize",
    "params": {
      "protocolVersion": "2024-11-05",
      "capabilities": {},
      "clientInfo": { "name": "example", "version": "1.0.0" }
    }
  }'
```

Discovery:

| URL | Purpose |
| - | - |
| `/.well-known/oauth-protected-resource` | Resource metadata for MCP clients |
| `/.well-known/oauth-authorization-server` | Authorization server metadata |
| `POST /oauth/register` | Dynamic client registration |
| `/.well-known/jwks.json` | JWT verification keys |

Supported scopes: `profile`, `accounts`, `read`, `write`.

Unauthenticated requests return `401` with a `WWW-Authenticate` header that points at the protected-resource metadata.

## Account membership

The account-scoped endpoint requires the authenticated user to be a member of `{account_id}`. Otherwise the server returns a forbidden MCP error.

Tools are further filtered by the user's account permissions. A caller only sees tools they are authorized to list and call.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.