Authentication and keys
One Bearer key acts for your whole organization. How to create, rotate and revoke it, and what a 401 means.
Made by SwooshConnect
Could not copy. Use View as Markdown instead.
What a key is
- A key is a Bearer token that starts with
sr_. It belongs to your organization, not to a person. - It acts on every account connected to the organization. There are no per-account or read-only keys.
- Creating a key is your consent for software that holds it to act on those accounts. Only give it to software you trust.
- An organization can hold at most 10 active keys. Revoke one to create another.
Use a key
curl -H "Authorization: Bearer $SWOOSHCONNECT_API_KEY" https://swooshrank.com/api/v1/connect/accountsCreate, rotate, revoke
- Create: portal, API keys, name the key, Create key. The full key is shown once. The list afterwards shows only a short prefix.
- Rotate: portal, API keys, Rotate on a key. It revokes the old key and makes a new one under the same name. Copy the new key at once.
- Revoke: portal, API keys, Revoke, then Confirm revoke. Anything using that key stops working immediately.
- Each row shows when the key was created and last used. Use it to find keys nobody needs.
One key per agent
Name each key after what uses it, for example a laptop, a CI runner or one deployed agent. Every agent you deploy from the portal gets its own key. If one leaks, you revoke that one.
When you get a 401
A missing, malformed, unknown or revoked key answers HTTP 401 with a WWW-Authenticate: Bearer challenge (the MCP endpoint adds realm and error details). The body uses the standard error envelope with the code unauthorized.
{ "error": { "code": "unauthorized", "message": "Invalid or missing API key" } }The body never echoes the key you sent. Check the header spelling, then check that the key was not revoked or rotated.
You pay for what you connect. Nothing else.