Skip to content

Authentication and permissions.

Keep public reading separate from workspace authority.

Updated

Public access

Catalog discovery, tool inspection and this documentation are available without an account. The public MCP endpoint is https://ai.agentik.cc/mcp/public. Public reading does not authorise a run.

MCP access

Connect to https://ai.agentik.cc/mcp with OAuth where your client supports it, or configure an Agentik API key in the client’s credential store. Use the installation instructions for the exact client configuration. A human completes account access and consent; an agent must not invent or bypass that consent.

REST access

Protected requests use Authorization: Bearer <Agentik API key>. Create, label and revoke keys in the workspace. New keys have no optional spending caps by default. Configure the supported caps and allowed-tool restrictions for your use case. Workspace membership, key permissions, rate limits, tool availability and balance still apply.

Recover from access failures

On 401, check the credential and the endpoint; use the OAuth metadata advertised in WWW-Authenticate for an OAuth MCP client. On 403, ask the workspace owner to review permissions. Repeating a forbidden call or changing tools does not grant authority.

Never place a token in a query string, copied prompt or public browser storage. If a credential is exposed, revoke it and create a replacement. Contact support with a request ID, never the secret.