Skip to main content
PATCH
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Path Parameters

deviceId
string
required

The device you hold.

Body

application/json

The lease you hold.

leaseId
string
required

The id the acquire returned.

Response

The same lease, with a later expiry.

A lease you hold. The fencing token is deliberately absent: it is the token the device itself checks to shut out a stale holder, it is stamped on your calls for you, and a client has no use for it.

deviceId
string
required

The device you now hold.

leaseId
string
required

The lease id. Send it on every action and on the release, and treat it as a credential: it is what identifies the holder, so anyone who has it can act as you and can give the device back. This is the only response that returns it, and it is returned to the caller that just took the lease.

acquiredAt
string
required

ISO-8601 instant the lease was granted.

expiresAt
string
required

ISO-8601 instant after which the lease no longer holds the device. Renew before it passes.