Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Path Parameters

userCode
string
required

The code from the terminal. Case, spaces and the hyphen are forgiven.

Body

application/json

Optional. Everything has a default.

scopes
enum<string>[]

A non empty subset of the scope vocabulary, within your own session's scopes.

Minimum array length: 1

A scope to grant.

Available options:
devices:read,
devices:act,
devices:lease,
runs:start,
orders:place,
apps:read,
apps:write,
apps:delete
ttlMs
integer

The key's lifetime in milliseconds, whole days only, counted from collection. Defaults to 15552000000 (180 days). The same name and unit as on POST /v1/api-keys.

Required range: 86400000 <= x <= 15552000000Must be a multiple of 86400000
name
string

The key's name. Defaults to CLI · <clientName>.

Required string length: 1 - 120

Response

Approved. The CLI collects the key on its next poll.

The sign-in after approval. The key is minted when the CLI next polls, not now.

userCode
string
required
clientName
string | null
required

What the CLI called itself, usually the computer's name. Unverified.

clientVersion
string | null
required

The CLI's version, as it reported it. Unverified.

requestedFromIp
string | null
required

The address the sign-in was opened from, as this service saw it. Compare it with where you are: a code someone sent you from elsewhere is the phishing case. Null when it could not be determined.

createdAt
string<date-time>
required
expiresAt
string<date-time>
required
status
enum<string>
required

Where this sign-in is. expired is judged on the service's clock.

Available options:
pending,
approved,
denied,
expired,
consumed
orgId
string
required

The organisation the key will act for: the approver's active one.

scopes
enum<string>[]
required

A scope the key will carry.

Available options:
devices:read,
devices:act,
devices:lease,
runs:start,
orders:place,
apps:read,
apps:write,
apps:delete
ttlMs
integer
required

The key's lifetime in milliseconds, whole days, counted from when the CLI collects it.

Required range: 86400000 <= x <= 15552000000
keyName
string
required