Authentication
The MCP Studio API uses two kinds of credential, for two different jobs.
| Credential | Prefix | Used for | Created in |
|---|---|---|---|
| API key | msk_live_ | Managing your account: every REST endpoint in this reference | Account > API Keys |
| Access token | mcps_live_ | Connecting an AI client to one private server's MCP endpoint | The server's page in the dashboard |
Public servers need neither to be queried. Anyone with the endpoint URL can connect.
API keys
Send the key as a bearer token on every request:
curl https://appatools.com/mcp-studio/api/billing/usage \
-H "Authorization: Bearer msk_live_..."
To create one:
- Open Account > API Keys in MCP Studio.
- Name the key and set Used from to Direct, or to the integration it is for.
- Under Can reach, choose Entire account or specific servers.
- Copy the key. It is shown exactly once; only a hash is stored, so a lost key can be replaced but never recovered.
Keep keys on a server. Never put one in frontend code, a mobile app, or a public repository. Revoke a key from the same screen if it leaks; revoking takes effect immediately.
A request with no key, a malformed key, or a revoked key returns:
{ "error": "Authentication required" }
with status 401.
Scoped keys
A key can be limited to specific servers. If it leaks, it cannot touch anything else.
| Account-wide key | Scoped key | |
|---|---|---|
| Servers it can read and change | All | Only the ones you picked |
GET /api/mcp/list | Every server | Only its servers |
| Creating servers | Allowed | 403 key_scoped |
| Deleting a custom tool | Allowed | 403 key_scoped, because it detaches the tool from every server |
| Retrieval rules | On any server | Only on its servers |
A server outside a key's scope returns 404, exactly as a server on another account does. The key is not told that it exists.
You can change a key's scope later without reissuing it.
Access tokens for private servers
A private server refuses every MCP request without a valid access token, including initialize and tools/list. Send it the same way:
Authorization: Bearer mcps_live_...
A server's first access token is returned once, in accessToken when you create a private server, or in issuedToken.plaintext when you make a server private or a private source makes it private. Create and revoke more on the server's page in the dashboard; a server can hold up to 10.
The owner's msk_live_ API key is also accepted on the MCP endpoint, which is convenient for testing. Give AI clients an access token instead, so a client config never holds a key that can manage your account.
See Private MCP servers for client setup.
Optional attribution headers
Integrations can identify themselves so usage is attributed correctly. All are optional and ignored when absent.
| Header | Max length | Example |
|---|---|---|
X-MCP-Studio-Partner | 40 | n8n |
X-MCP-Studio-Partner-Version | 40 | 1.4.0 |
X-MCP-Studio-Install-Channel | 40 | community-nodes |
X-MCP-Studio-Workspace-Id | 120 | Your workspace identifier |
X-MCP-Studio-Integration-Id | 120 | Your integration identifier |
X-MCP-Studio-Campaign-Id | 120 | A campaign identifier |
Browser requests
The API answers cross-origin requests only from this documentation site, so the interactive console works and nothing else can call the API from a browser with a visitor's session. Call it from your own backend.