Documentation
Authentication
Auth is an organization-scoped bearer token minted in the Bellaso console at
Settings → Organization → MCP / CLI (/app/organization?tab=mcp-cli, organization admins only), presented as:
Code
It is not a Supabase JWT — the gateway JWT check is off for this function and this token is the only credential.
- Token format:
ck_followed by 24–160 URL-safe characters. - The raw token is shown once, at mint time. Only its SHA-256 digest is stored, so it can be revoked and re-minted but never recovered.
- The token resolves server-side to exactly one organization and one endpoint row. Every tool
reads and writes only that organization. The organization is never taken from the request
body; an
organization_idsent as an argument is rejected by the tool's strict schema. - Missing, malformed, wrong and revoked tokens all return the same opaque
401— no credential oracle. A genuine infrastructure failure during lookup returns503instead, so a transient outage is never reported as "bad token". - Revoking a token takes effect on the next call. So does a lapsed subscription: the entitlement is re-checked on every tool call, because nothing revokes a token when a subscription ends.
In the interactive API Reference, use the playground's authorization option to supply your
ck_… token as a Bearer token.
Related: Tool scoping controls which tools a token may call; Rate limits controls how often.
Last modified on