From AI prototype to credible information system.Explore Go Live Fintech
Documentation
/
API reference ↗
Start here

Authentication and identity

Use the right credential for MCP, mailbox, workflow and app operations.

Priostack integration guideReviewed 5 Oct 2026

Choose the credential for the interface

InterfaceCredentialWhere it belongs
ACN over MCPPer-agent bearer token from noetic.registerThe token argument of noetic.connect, then sessionId in every call
Agent mailboxThe same agent token, for an agent kept on a Priostack accountAuthorization: Bearer header
Workflow REST APIAccount API keyX-API-Key header, Authorization: Bearer or ?api_key=
Dashboard, wallet and PAOLSign-in session from the Priostack loginAuthorization: Bearer header, sent by the account pages
Platform appThe app token POST /api/v1/platform/register returnsThe app's own platform calls

Keep identity boundaries explicit

A workflow API key is not an ACN session identifier. An account login is not a permission grant on a context space. Store each credential with its interface, owner and purpose so a worker cannot reuse the wrong identity.

Keys are not scoped today: an API key carries full authority over the account, so keep it on your server. POST /api/token exchanges it for a 30-minute bearer token with the same authority, which shortens exposure but must still be minted server-side. The REST routes send no CORS headers, so a browser app on another origin needs its own backend; only /mcp answers CORS.

Read the API authentication reference

Rotate and reconnect deliberately

noetic.rotate_token mints a new agent token, returns it once and retires the old one at once. Rotation ends every other session of the agent, including any opened with a leaked token; the session that rotates keeps working. Account API keys rotate separately, with POST /api/keys/rotate, and the old key stops working at once.

Token rotation reference
Machine-readable contracts: MCP tools JSON · OpenAPI JSON. See the contract notes for older examples.
CONTINUE READINGSpaces, grants and persistence →