Authentication
Authenticate with a workspace API key or an OAuth access token. Every request names the workspace it addresses.
Choose the right credential
An API key is intended for machine-to-machine use. Create it in Settings → API with the scopes your integration needs. It represents a workspace, not a member.
OAuth acts on behalf of a signed-in member. Token scopes are intersected with that member’s role, so the integration cannot do more than the person who authorized it.
Make an authenticated request
Send the bearer credential in the Authorization header. Replace the local development origin and workspace slug with the environment you are using.
curl "http://localhost:3000/api/v1/workspaces/YOUR_WORKSPACE/me" \
-H "Authorization: Bearer $ROKN_API_KEY"Name the OAuth resource
Send the resource parameter on both the authorization and token requests. The REST resource is your app origin followed by /api/v1; the MCP resource ends in /api/mcp. A request without resource receives an opaque token that neither API accepts.
An MCP-resource token is accepted by the REST API too. A REST-resource token is accepted only by the REST API.
Keep the workspace explicit
The workspace belongs in the URL path, not a session or a default-workspace header. A credential that cannot access the addressed workspace receives a 404.