Skip to main content
Every /v1 request needs an API key from the dashboard:

Key format

Keys are generated in internal/core/auth/auth.go: the prefix robe_ plus 32 random bytes encoded as 64 hex characters. Agent keys created for MCP use robe_agent_ plus the same 64 hex characters — they still start with robe_, so existing auth accepts them. The full secret is shown once at creation and stored as a SHA-256 hash. Revoke unused keys from the dashboard. Hosted MCP (https://api.robase.dev/mcp) uses the same Bearer header. Prefer a dedicated Agent key and revoke it if it leaks. See AI agents. There is no separate test-mode prefix. Dashboard test send buttons spend real credits and deliver to real numbers.

Scopes

A key belongs to one workspace. Dashboard routes use session cookies, not these keys. Each key also has scopes, which decide which /v1 endpoints and MCP tools it may call:
  • An Agent key must be given at least one scope when you create it.
  • A standard key created without scopes has full access.
  • Keys created before scopes existed keep full access. The dashboard marks such Agent keys Legacy full access. To narrow one, create a new Agent key with the scopes it needs and revoke the old one.
A call without the scope it needs returns 403 with error.type: insufficient_scope and error.required_scope. Over MCP, tools/list shows only the tools the key may call.

Official SDKs

Pass the key into the client. The SDKs attach Authorization and generate an Idempotency-Key on every POST:

Base URL