Skip to main content
GET
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Query Parameters

limit
integer

How many to return, 1 to 100. Defaults to 50. Above the maximum is refused, never quietly reduced: page with the cursor instead.

Required range: 1 <= x <= 100
before
string

Opaque cursor from a previous page's nextBefore. Treat it as opaque: its form is not part of this contract. Send it only when you have one, because an empty value is refused rather than read as no cursor. Computed notifications appear on the first page only, so a later page carries stored rows alone.

Response

One page of notifications, newest first, and the bell's number.

notifications
object[]
required
actionRequiredUnread
integer
required

Unread notifications that need somebody to act, over the whole org and not just this page.

nextBefore
string

Cursor for the next, older page. Absent when this page reached the end.