Skip to main content
AmDital’s REST API (CRM, HRMS, Finance, and the rest — see API Reference) authenticates via a session bearer token today. A separate, narrower API-key mechanism (sk_...) exists for MCP only.

Session bearer token (primary method)

The web app authenticates via an httpOnly session cookie set at login — not a client-readable token, so browser JS never calls a session-fetching API directly. Server-side route handlers read the verified session and forward it as a bearer token to the API:

API key (MCP only)

A long-lived sk_... API key authenticates the MCP endpoint specifically — it is not accepted by any other route today:
See MCP Authentication for the full key format and scopes.

Rate limits

Rate limits are applied per route category, not per plan — every workspace on every plan (Free, Starter, Pro, Business, Enterprise) gets the same limits today: See Rate Limits & Pagination for the full breakdown.