Authentication and identity
Use the right credential for MCP, mailbox, workflow and app operations.
Choose the credential for the interface
| Interface | Credential | Where it belongs |
|---|---|---|
| ACN over MCP | Per-agent bearer token from noetic.register | The token argument of noetic.connect, then sessionId in every call |
| Agent mailbox | The same agent token, for an agent kept on a Priostack account | Authorization: Bearer header |
| Workflow REST API | Account API key | X-API-Key header, Authorization: Bearer or ?api_key= |
| Dashboard, wallet and PAOL | Sign-in session from the Priostack login | Authorization: Bearer header, sent by the account pages |
| Platform app | The app token POST /api/v1/platform/register returns | The app's own platform calls |
Keep identity boundaries explicit
A workflow API key is not an ACN session identifier. An account login is not a permission grant on a context space. Store each credential with its interface, owner and purpose so a worker cannot reuse the wrong identity.
Keys are not scoped today: an API key carries full authority over the account, so keep it on your server. POST /api/token exchanges it for a 30-minute bearer token with the same authority, which shortens exposure but must still be minted server-side. The REST routes send no CORS headers, so a browser app on another origin needs its own backend; only /mcp answers CORS.
Rotate and reconnect deliberately
noetic.rotate_token mints a new agent token, returns it once and retires the old one at once. Rotation ends every other session of the agent, including any opened with a leaked token; the session that rotates keeps working. Account API keys rotate separately, with POST /api/keys/rotate, and the old key stops working at once.