Reference

Authentication

The AEO MCP server is private. Every request is authenticated with a per-user Bearer API key, resolved to your account and scoped to your projects.

Bearer keys

Create keys from Settings → API keys. Send the key on every request:

header
Authorization: Bearer aeo_xxxxxxxx

How keys are stored

  • Only a short prefix is kept in readable form so you can identify a key in the list.
  • The full key is hashed with SHA-256 before storage — it is shown to you once, at creation, and never again.
  • Keys can carry an expiry and can be disabled or revoked at any time.
  • Keys are per-user and scoped to the projects that user owns.

Plan gating

MCP access requires the Pro plan or higher. Requests are checked against your entitlement on every call, so a downgrade takes effect immediately.

Error responses

StatusMeaning
401Missing, invalid, expired or revoked key.
403Valid key, but the plan doesn’t include MCP access.
405A method other than POST was used on /mcp.