# Authentication

Auth is an **organization-scoped bearer token** minted in the Bellaso console at
**Settings → Organization → MCP / CLI** (`/app/organization?tab=mcp-cli`, organization admins only), presented as:

```http
Authorization: Bearer ck_…
```

It is *not* a Supabase JWT — the gateway JWT check is off for this function and this token is the
only credential.

- Token format: `ck_` followed by 24–160 URL-safe characters.
- The raw token is shown **once, at mint time**. Only its SHA-256 digest is stored, so it can be
  revoked and re-minted but never recovered.
- The token resolves server-side to exactly one organization and one endpoint row. **Every tool
  reads and writes only that organization.** The organization is never taken from the request
  body; an `organization_id` sent as an argument is rejected by the tool's strict schema.
- Missing, malformed, wrong and revoked tokens all return the same opaque `401` — no credential
  oracle. A genuine infrastructure failure during lookup returns `503` instead, so a transient
  outage is never reported as "bad token".
- **Revoking a token takes effect on the next call.** So does a lapsed subscription: the
  entitlement is re-checked on every tool call, because nothing revokes a token when a
  subscription ends.

:::tip

In the interactive [API Reference](/api), use the playground's authorization option to supply your
`ck_…` token as a Bearer token.

:::

Related: [Tool scoping](/tool-scoping) controls *which* tools a token may call;
[Rate limits](/rate-limits) controls *how often*.
