Skip to main content
The AmDital MCP server (POST /api/v1/mcp) accepts two authentication methods on the same endpoint. Send either as a Bearer token in the Authorization header — the server detects which one you’re using automatically.
Never share an API key or bearer token in public repositories, client-side code, or screenshots. An API key does not expire on its own unless you set an expiry — treat it with the same care as a database password.
Create a key from Settings → Developer in any workspace (admin/owner role required): click Create API Key, choose one or more scopes, optionally set an expiry, and copy the key immediately — like most API-key systems, the full value is shown once and only its hash is stored, so it cannot be retrieved again later. Revoke a key from the same page at any time; revocation takes effect on the next request.
An API key can never reach a workspace other than the one it was issued for, regardless of tool arguments — the server resolves the workspace from the key itself, never from anything the caller sends.

Path 2 — Workspace bearer token (short-lived, for interactive sessions)

Access tokens are short-lived (15 minutes). A 30-day refresh token backs the session — your client must refresh and reconnect when the access token expires; long-running agents should refresh proactively rather than waiting for a 401. This is the same session token AmDital’s own web app uses.

Error responses