Authentication
Every request needs an API key or, for AI apps connected through MCP, an OAuth access token.
API keys
Send the key as a Bearer token in the Authorization header:
http
Authorization: Bearer YOUR_API_KEY- Create, rotate, and delete keys in Settings → API Keys in the YouViCo app.
- Workspace owners, managers, and members can create keys.
- Each key belongs to one workspace and reaches only that workspace.
- A key acts with your own roles, limited to the scopes you give it.
Warning
Keep your keys secret. If a key leaks, rotate or delete it right away.
OAuth access tokens
When you connect an AI app through MCP, the app receives an OAuth access token instead of an API key. The token works like an API key: it belongs to the workspace you chose and carries the scopes you approved. The app sends and renews the token for you.
Check a credential
Ping returns the workspace and scopes of the API key or OAuth access token you send.