/v1 request needs an API key from the dashboard:
Key format
Keys are generated ininternal/core/auth/auth.go: the prefix robe_ plus 32 random bytes encoded as 64 hex characters. Agent keys created for MCP use robe_agent_ plus the same 64 hex characters — they still start with robe_, so existing auth accepts them. The full secret is shown once at creation and stored as a SHA-256 hash. Revoke unused keys from the dashboard.
Hosted MCP (https://api.robase.dev/mcp) uses the same Bearer header. Prefer a dedicated Agent key and revoke it if it leaks. See AI agents.
There is no separate test-mode prefix. Dashboard test send buttons spend real credits and deliver to real numbers.
Scopes
A key belongs to one workspace. Dashboard routes use session cookies, not these keys. Each key also has scopes, which decide which/v1 endpoints and MCP tools it may call:
- An Agent key must be given at least one scope when you create it.
- A standard key created without scopes has full access.
- Keys created before scopes existed keep full access. The dashboard marks such Agent keys Legacy full access. To narrow one, create a new Agent key with the scopes it needs and revoke the old one.
403 with error.type: insufficient_scope and error.required_scope. Over MCP, tools/list shows only the tools the key may call.
Official SDKs
Pass the key into the client. The SDKs attachAuthorization and generate an Idempotency-Key on every POST: