Skip to content

Authentication ​

Every request needs an API key or, for AI apps connected through MCP, an OAuth access token.

API keys ​

Send the key as a Bearer token in the Authorization header:

http
Authorization: Bearer YOUR_API_KEY
  • Create, rotate, and delete keys in Settings → API Keys in the YouViCo app.
  • Workspace owners, managers, and members can create keys.
  • Each key belongs to one workspace and reaches only that workspace.
  • A key acts with your own roles, limited to the scopes you give it.

Warning

Keep your keys secret. If a key leaks, rotate or delete it right away.

OAuth access tokens ​

When you connect an AI app through MCP, the app receives an OAuth access token instead of an API key. The token works like an API key: it belongs to the workspace you chose and carries the scopes you approved. The app sends and renews the token for you.

Check a credential ​

Ping returns the workspace and scopes of the API key or OAuth access token you send.