1. Send a code
Ask the owner for the exact email address and approval before starting. The next request emails a sign-in code to that address:2. Complete sign-in
access_token, refresh_token, organization_id, and session_id. Keep credentials out of prompts, logs, and source control.
3. Create an API key
Use the access token to create a key for repeated automation:Revoke access
Revoke the bearer credential used for the request:GET /api/api-keys and DELETE /api/api-keys/{id} with an access token to list and revoke API keys.
MCP authentication is separate
An MCP client follows protected-resource metadata athttps://api.cool.computer/.well-known/oauth-protected-resource/mcp and completes its own OAuth flow. That token authorizes only the MCP resource for an existing owner. Write tools also check the owner’s live cool-computers:operate permission. The token does not authorize the HTTP API.
Read the authentication reference for credential discovery, errors, and interactive sign-in requirements.
