Skip to guide

Reference

API and keys

Which token to use for sessions, MCP and log ingestion, with endpoint, lifecycle and error examples.

Last updated

On this page

Escanor's dashboard HTTP base is https://api.escanor.in/api/v1. MCP and OIDC have their own addresses. Each kind of key works only for its own purpose, as listed below.

Credential types

CredentialUsed forImportant limit
User session access tokenDashboard/app HTTP routesExpires and is renewed by the application's refresh flow.
MCP keyRemote MCP integration toolsDoes not replace a dashboard sign-in.
OIDC access tokenIts granted scopes and resource audienceDo not use an ID token as an API credential.
Log ingest token/observability/ingestSubmission only; cannot read logs or sign in.
Provider API key/tokenThe corresponding integration connectionNot an Escanor session token.

Manage MCP connections under MCP or Settings > Developer > API and MCP keys. Escanor shows a new token only once. Give each client a distinct name. Rotation replaces the token immediately; update that client deliberately. Revocation stops that key, without deleting the connected provider's resources.

Dashboard requests

Dashboard routes authenticate a user session. The app sends workspace/organization context headers for compatibility. Project routes derive the workspace from the authenticated user; these headers do not switch workspaces or authorize another workspace. Session context selection currently has single-workspace behavior.

curl -fsS https://api.escanor.in/api/v1/auth/session \
  -H 'Authorization: Bearer YOUR_SESSION_ACCESS_TOKEN'

It returns session/bootstrap information for that user. Treat it as private account data. Do not copy real access or refresh tokens from storage into public examples. Prefer the application's supported session client instead of writing a new refresh loop.

curl -fsS 'https://api.escanor.in/api/v1/projects?search=example' \
  -H 'Authorization: Bearer YOUR_SESSION_ACCESS_TOKEN' \
  -H 'X-Workspace-Id: YOUR_WORKSPACE_ID' \
  -H 'X-Organization-Id: YOUR_ORGANIZATION_ID'

The context headers are for client compatibility and do not authorize anything on their own. See Projects for provider restrictions.

Public endpoint map

SurfaceExamplesAuthentication
Sessions/auth/session, /auth/sessionsUser session
Projects/projects, /projects/{id}/deploymentsUser session + workspace
Operations/deployments, /incidents, /autopilot/runsUser session + role/policy
MCP setup/agent/mcp/config, /agent/mcp/connectionsUser session
MCP installPOST /agent/mcp/install with {"name":"Example client"}User session; returns token/config once
Log ingestPOST /observability/ingestDedicated ingest token
OIDC discoveryhttps://api.escanor.in/.well-known/openid-configurationPublic
MCP resource metadatahttps://mcp.escanor.in/.well-known/oauth-protected-resourcePublic

This page does not promise versioned stability for every dashboard endpoint. Check response shapes and errors; provider-specific operations differ. Use OIDC for third-party authentication and MCP for integration automation.

Session and key lifecycle

GET /auth/sessions returns session IDs and creation/expiry/current-session metadata. DELETE /auth/sessions/{session_id} ends a selected session; POST /auth/sessions/revoke-others ends others. These routes require the user session and cannot be used with an ingest key.

For MCP, POST /agent/mcp/connections/{token_id}/rotate returns a replacement configuration; DELETE /tokens/{token_id} revokes it. Copy the new value only to that client and remove old credentials from its configuration. Keep credentials in a secret store/environment configuration, not prompts or version control.

Errors and retry behavior

Status/resultRecovery
401Check credential type, expiry and revocation. Sign in/refresh using the appropriate flow.
403Check role, scope, audience and provider access; do not retry with broader privileges blindly.
404Verify route/resource identifier and whether it is visible to this account.
422Read validation field details and correct the body/query.
429Respect Retry-After when provided and reduce frequency.
5xx or network errorRetry reads with backoff; inspect the target before retrying a write.
HTTP 200 with success:false or a tool errorTreat as failure; do not infer success from HTTP status alone.

Limits vary by endpoint and plan. Never store credentials in example output. Related: Log ingestion, Permissions, Accounts and sessions.

Need help? Contact support with a redacted error and the affected version.