Appa Tools documentation for MCP Studio, including setup, guides, concepts, and API-related reference content.

Skip to main content

Authentication

The MCP Studio API uses two kinds of credential, for two different jobs.

CredentialPrefixUsed forCreated in
API keymsk_live_Managing your account: every REST endpoint in this referenceAccount > API Keys
Access tokenmcps_live_Connecting an AI client to one private server's MCP endpointThe server's page in the dashboard

Public servers need neither to be queried. Anyone with the endpoint URL can connect.

API keys​

Send the key as a bearer token on every request:

curl https://appatools.com/mcp-studio/api/billing/usage \
-H "Authorization: Bearer msk_live_..."

To create one:

  1. Open Account > API Keys in MCP Studio.
  2. Name the key and set Used from to Direct, or to the integration it is for.
  3. Under Can reach, choose Entire account or specific servers.
  4. Copy the key. It is shown exactly once; only a hash is stored, so a lost key can be replaced but never recovered.

Keep keys on a server. Never put one in frontend code, a mobile app, or a public repository. Revoke a key from the same screen if it leaks; revoking takes effect immediately.

A request with no key, a malformed key, or a revoked key returns:

{ "error": "Authentication required" }

with status 401.

Scoped keys​

A key can be limited to specific servers. If it leaks, it cannot touch anything else.

Account-wide keyScoped key
Servers it can read and changeAllOnly the ones you picked
GET /api/mcp/listEvery serverOnly its servers
Creating serversAllowed403 key_scoped
Deleting a custom toolAllowed403 key_scoped, because it detaches the tool from every server
Retrieval rulesOn any serverOnly on its servers

A server outside a key's scope returns 404, exactly as a server on another account does. The key is not told that it exists.

You can change a key's scope later without reissuing it.

Access tokens for private servers​

A private server refuses every MCP request without a valid access token, including initialize and tools/list. Send it the same way:

Authorization: Bearer mcps_live_...

A server's first access token is returned once, in accessToken when you create a private server, or in issuedToken.plaintext when you make a server private or a private source makes it private. Create and revoke more on the server's page in the dashboard; a server can hold up to 10.

The owner's msk_live_ API key is also accepted on the MCP endpoint, which is convenient for testing. Give AI clients an access token instead, so a client config never holds a key that can manage your account.

See Private MCP servers for client setup.

Optional attribution headers​

Integrations can identify themselves so usage is attributed correctly. All are optional and ignored when absent.

HeaderMax lengthExample
X-MCP-Studio-Partner40n8n
X-MCP-Studio-Partner-Version401.4.0
X-MCP-Studio-Install-Channel40community-nodes
X-MCP-Studio-Workspace-Id120Your workspace identifier
X-MCP-Studio-Integration-Id120Your integration identifier
X-MCP-Studio-Campaign-Id120A campaign identifier

Browser requests​

The API answers cross-origin requests only from this documentation site, so the interactive console works and nothing else can call the API from a browser with a visitor's session. Call it from your own backend.