> ## Documentation Index
> Fetch the complete documentation index at: https://cool.computer/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Cool Computers API authentication

> Sign up or sign in to Cool Computers, create an API key, and keep HTTP and MCP credentials separate.

The HTTP API uses the same email-code flow for new and existing Cool Computers accounts. Completing verification creates your account if needed.

## 1. Send a code

Ask the owner for the exact email address and approval before starting. The next request emails a sign-in code to that address:

```sh theme={null}
curl https://api.cool.computer/api/auth/email/start \
  -H 'content-type: application/json' \
  --data '{"email":"owner@example.com"}'
```

Do not repeat the request while waiting. Ask the owner for the latest six-digit code.

## 2. Complete sign-in

```sh theme={null}
curl https://api.cool.computer/api/auth/email/complete \
  -H 'content-type: application/json' \
  --data '{"email":"owner@example.com","code":"123456"}'
```

The response returns `access_token`, `refresh_token`, `organization_id`, and `session_id`. Keep credentials out of prompts, logs, and source control.

## 3. Create an API key

Use the access token to create a key for repeated automation:

```sh theme={null}
curl https://api.cool.computer/api/api-keys \
  -H "authorization: Bearer $ACCESS_TOKEN" \
  -H 'content-type: application/json' \
  --data '{"name":"automation"}'
```

The API returns the secret once. API-key management requires an owner access token. An API key cannot create another API key.

## Revoke access

Revoke the bearer credential used for the request:

```sh theme={null}
curl -X POST https://api.cool.computer/api/auth/logout \
  -H "authorization: Bearer $ACCESS_TOKEN"
```

Use `GET /api/api-keys` and `DELETE /api/api-keys/{id}` with an access token to list and revoke API keys.

## MCP authentication is separate

An MCP client follows protected-resource metadata at `https://api.cool.computer/.well-known/oauth-protected-resource/mcp` and completes its own OAuth flow. That token authorizes only the MCP resource for an existing owner. Write tools also check the owner's live `cool-computers:operate` permission. The token does not authorize the HTTP API.

Read the [authentication reference](https://www.cool.computer/auth.md) for credential discovery, errors, and interactive sign-in requirements.
