> ## Documentation Index
> Fetch the complete documentation index at: https://docs.amdital.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Authenticate with AmDital using API keys or a session bearer token.

AmDital's REST API (CRM, HRMS, Finance, and the rest — see [API Reference](/api-reference)) authenticates via a session bearer token today. A separate, narrower API-key mechanism (`sk_...`) exists for MCP only.

## Session bearer token (primary method)

The web app authenticates via an httpOnly session cookie set at login — not a client-readable token, so browser JS never calls a session-fetching API directly. Server-side route handlers read the verified session and forward it as a bearer token to the API:

```ts theme={null}
// Server-side only — the session cookie is httpOnly
const accessToken = await getServerAccessToken()

// Works against any resource route — see API Reference for the full collection list
const response = await fetch('https://api.amdital.com/api/v1/{collection}', {
  headers: {
    Authorization: `Bearer ${accessToken}`,
  },
})
```

## API key (MCP only)

A long-lived `sk_...` API key authenticates the MCP endpoint specifically — it is not accepted by any other route today:

```bash theme={null}
curl https://api.amdital.com/api/v1/mcp \
  -H "Authorization: Bearer amdital_sk_live_..."
```

See [MCP Authentication](/mcp/auth) for the full key format and scopes.

## Rate limits

Rate limits are applied per route category, not per plan — every workspace on every plan (Free,
Starter, Pro, Business, Enterprise) gets the same limits today:

| Route | Limit |
| - | - |
| `/v1/auth-next/login` | 10 req/min |
| `/v1/auth-next/refresh` | 30 req/min |
| `/api/ami/*` (AI) | 20 req/min |
| `/api/reports/*` | 5 req / 5 min |
| Everything else | No app-level limit today (still requires a valid session/API key) |

See [Rate Limits & Pagination](/rate-limits) for the full breakdown.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.