Documentation

Authentication

Auth is an organization-scoped bearer token minted in the Bellaso console at Settings → Organization → MCP / CLI (/app/organization?tab=mcp-cli, organization admins only), presented as:

Code
Authorization: Bearer ck_…

It is not a Supabase JWT — the gateway JWT check is off for this function and this token is the only credential.

  • Token format: ck_ followed by 24–160 URL-safe characters.
  • The raw token is shown once, at mint time. Only its SHA-256 digest is stored, so it can be revoked and re-minted but never recovered.
  • The token resolves server-side to exactly one organization and one endpoint row. Every tool reads and writes only that organization. The organization is never taken from the request body; an organization_id sent as an argument is rejected by the tool's strict schema.
  • Missing, malformed, wrong and revoked tokens all return the same opaque 401 — no credential oracle. A genuine infrastructure failure during lookup returns 503 instead, so a transient outage is never reported as "bad token".
  • Revoking a token takes effect on the next call. So does a lapsed subscription: the entitlement is re-checked on every tool call, because nothing revokes a token when a subscription ends.

In the interactive API Reference, use the playground's authorization option to supply your ck_… token as a Bearer token.

Related: Tool scoping controls which tools a token may call; Rate limits controls how often.

Last modified on