Authentication
The AEO MCP server is private. Every request is authenticated with a per-user Bearer API key, resolved to your account and scoped to your projects.
Bearer keys
Create keys from Settings → API keys. Send the key on every request:
header
Authorization: Bearer aeo_xxxxxxxxHow keys are stored
- Only a short prefix is kept in readable form so you can identify a key in the list.
- The full key is hashed with SHA-256 before storage — it is shown to you once, at creation, and never again.
- Keys can carry an expiry and can be disabled or revoked at any time.
- Keys are per-user and scoped to the projects that user owns.
Plan gating
MCP access requires the Pro plan or higher. Requests are checked against your entitlement on every call, so a downgrade takes effect immediately.
Error responses
| Status | Meaning |
|---|---|
| 401 | Missing, invalid, expired or revoked key. |
| 403 | Valid key, but the plan doesn’t include MCP access. |
| 405 | A method other than POST was used on /mcp. |