Skip to main content
All API requests require a Bearer token in the Authorization header.
Only tokens beginning with sk_ are treated as API keys. Tokens beginning with orgo_mcp_ are issued to MCP clients through the MCP sign-in flow, and reach only computer, file, and workspace-read endpoints. Any other Bearer value is ignored, and the request falls through to browser session authentication. A server-to-server caller has no browser session, so the request fails with 401.

Get your API key

  1. Sign in at orgo.ai/start.
  2. Open orgo.ai/settings/credentials.
  3. In the API keys section, click New key.
  4. Pick a scope (described in Key scopes) and a name, then select Create key.
  5. Copy the plaintext value. It is shown once.

Key scopes

Every API key is either account-wide or pinned to a single workspace.

What a workspace-scoped key can do

Scope is checked on every request, before the endpoint runs. A workspace-scoped key:
  • Can call the computer, workspace, file, and screenshot endpoints, but only for its own workspace and the computers and files in it. Any other workspace ID, computer ID, or file ID is refused.
  • Sees only its own workspace in List workspaces.
  • Cannot create workspaces.
  • Cannot call any other endpoint, including templates, chat completions, and threads.
  • Can list API keys, filtered to its own workspace, but cannot create or delete keys.
A refused request carries one of these messages:
The status is 403 on most endpoints. Some endpoints answer every failed access check with 401 instead, with the same body. Each endpoint’s page lists which one it returns. The OpenAI-compatible surface (/v1/...) returns its own 401 envelope, described in the note under Error responses. A few endpoints, such as Upload file, add a second check with a richer body:
Match on the workspace_scope_mismatch text, which every variant contains, rather than on the full message.

Workspace roles

The same check applies your role in the workspace, whether you authenticate with a key or a session. An invited member with view-only access can read the workspace and its computers but cannot change them. A write attempt is refused with This workspace is view-only. Ask the owner for write access (workspace_read_only). A workspace you neither own nor belong to is refused with You do not have access to this workspace.

Rotating a key

Generate a new key, update your client to use it, then delete the old one. Both keys work while you migrate. Key list, creation, and deletion live at orgo.ai/settings/credentials. There is no documented public endpoint for managing keys.
Store API keys securely. Never commit them to version control or share them publicly. Rotate immediately if a key is exposed.

Examples

Environment variables

.env

Error responses

The OpenAI-compatible surface (/v1/chat/completions and /v1/threads) uses a nested error envelope instead: { "error": { "type": "authentication_error", "message": "…", "code": "invalid_api_key" } }. It returns that one body with 401 for every authentication or access failure, including a missing or invalid key and a workspace-scoped key.
See Troubleshooting for the full error reference and recovery steps.

Security tips

  • Use environment variables. Never hardcode keys.
  • Add .env to .gitignore.
  • Create a separate workspace-scoped key per integration, keeping in mind the limits above.
  • Rotate keys when team members leave.

Need help?

Email spencer@orgo.ai. Include the request_id from the error response when the response carries one.