Authentication
API keys for code and coding agents, OAuth 2.1 for apps like ChatGPT and Claude.
API keys
Send your key as a Bearer token on every REST request and on /mcp:
Authorization: Bearer rah_live_…
Keys are stored only as hashes, so we can't show one again. Create, name and revoke keys in the dashboard. Sign in to the dashboard with any active key.
OAuth 2.1
Apps that can't send custom headers, such as ChatGPT and Claude connectors, use OAuth. The MCP endpoint returns a 401 with a WWW-Authenticate header pointing at the resource metadata, and clients discover everything else:
| Endpoint | URL |
|---|---|
| Protected resource metadata | /.well-known/oauth-protected-resource/mcp |
| Authorization server metadata | /.well-known/oauth-authorization-server |
| Authorize (consent screen) | /authorize |
| Token | /token |
| Dynamic client registration | /register (Client ID Metadata Documents are also supported) |
Authorization code flow with PKCE (S256) only. Scope: calls. On the consent screen, users either create a new account or link an existing one with its API key.