# MCP authentication and workspaces


MCP supports interactive WorkOS AuthKit sign-in, personal API keys for headless clients, and delegated agent credentials. Every request is independently authenticated. The server checks current authority when you call a tool.

## Interactive OAuth

Complete AuthKit sign-in and approve the requested Organization, Workspaces, scopes and bundles. The durable consent grant limits the client's access and is intersected with your live permissions. Older single-Workspace grants keep their Workspace pin. Expired or revoked consent requires reconnection; the server does not select a different Workspace.

## Personal API keys

Create a key in **Settings → Personal → API keys** and send `Authorization: Bearer szp_…`. A full-account key follows your own authorized access; a restricted key also applies its configured Organization, Workspace and permission limits. Losing access ends the key's reach there. Old `sk_` keys remain usable until rotated, expired or revoked; legacy `sz_` keys are rejected.

## Workspace selection

Use `list_workspaces` to discover authorized handles and supply `workspaceId` on data calls. The [tool reference](/mcp/tools) displays personal-key and OAuth/delegated-agent input variants.

## Permissions and recovery

Tool discovery is public metadata. Execution still requires principal admission, live membership/access, the operation's permission, and any delegated restrictions. A `403` means the credential lacks authority; inspect current roles and consent. A reconnect error requires renewed authentication or consent.

The generated [authentication and authorization guide](/authentication) and [auth.md](/auth.md) contain the current RBAC roles, permission classes and endpoint policies. See [Architecture](/architecture) for the complete request path.

