Authorization header.
sk_ are treated as API keys. Tokens beginning with orgo_mcp_ are issued to MCP clients through the MCP sign-in flow, and reach only computer, file, and workspace-read endpoints. Any other Bearer value is ignored, and the request falls through to browser session authentication. A server-to-server caller has no browser session, so the request fails with 401.
Get your API key
- Sign in at orgo.ai/start.
- Open orgo.ai/settings/credentials.
- In the API keys section, click New key.
- Pick a scope (described in Key scopes) and a name, then select Create key.
- Copy the plaintext value. It is shown once.
Key scopes
Every API key is either account-wide or pinned to a single workspace.What a workspace-scoped key can do
Scope is checked on every request, before the endpoint runs. A workspace-scoped key:- Can call the computer, workspace, file, and screenshot endpoints, but only for its own workspace and the computers and files in it. Any other workspace ID, computer ID, or file ID is refused.
- Sees only its own workspace in List workspaces.
- Cannot create workspaces.
- Cannot call any other endpoint, including templates, chat completions, and threads.
- Can list API keys, filtered to its own workspace, but cannot create or delete keys.
403 on most endpoints. Some endpoints answer every failed access check with 401 instead, with the same body. Each endpoint’s page lists which one it returns. The OpenAI-compatible surface (/v1/...) returns its own 401 envelope, described in the note under Error responses.
A few endpoints, such as Upload file, add a second check with a richer body:
workspace_scope_mismatch text, which every variant contains, rather than on the full message.
Workspace roles
The same check applies your role in the workspace, whether you authenticate with a key or a session. An invited member with view-only access can read the workspace and its computers but cannot change them. A write attempt is refused withThis workspace is view-only. Ask the owner for write access (workspace_read_only). A workspace you neither own nor belong to is refused with You do not have access to this workspace.
Rotating a key
Generate a new key, update your client to use it, then delete the old one. Both keys work while you migrate. Key list, creation, and deletion live at orgo.ai/settings/credentials. There is no documented public endpoint for managing keys.Examples
Environment variables
.env
Error responses
The OpenAI-compatible surface (
/v1/chat/completions and /v1/threads) uses a nested error envelope instead: { "error": { "type": "authentication_error", "message": "…", "code": "invalid_api_key" } }. It returns that one body with 401 for every authentication or access failure, including a missing or invalid key and a workspace-scoped key.Security tips
- Use environment variables. Never hardcode keys.
- Add
.envto.gitignore. - Create a separate workspace-scoped key per integration, keeping in mind the limits above.
- Rotate keys when team members leave.
Need help?
Email spencer@orgo.ai. Include therequest_id from the error response when the response carries one.