Skip to main content
The HTTP API uses the same email-code flow for new and existing Cool Computers accounts. Completing verification creates your account if needed.

1. Send a code

Ask the owner for the exact email address and approval before starting. The next request emails a sign-in code to that address:
Do not repeat the request while waiting. Ask the owner for the latest six-digit code.

2. Complete sign-in

The response returns access_token, refresh_token, organization_id, and session_id. Keep credentials out of prompts, logs, and source control.

3. Create an API key

Use the access token to create a key for repeated automation:
The API returns the secret once. API-key management requires an owner access token. An API key cannot create another API key.

Revoke access

Revoke the bearer credential used for the request:
Use GET /api/api-keys and DELETE /api/api-keys/{id} with an access token to list and revoke API keys.

MCP authentication is separate

An MCP client follows protected-resource metadata at https://api.cool.computer/.well-known/oauth-protected-resource/mcp and completes its own OAuth flow. That token authorizes only the MCP resource for an existing owner. Write tools also check the owner’s live cool-computers:operate permission. The token does not authorize the HTTP API. Read the authentication reference for credential discovery, errors, and interactive sign-in requirements.