API Authentication & Security
Authenticate API and MCP requests using secure site-specific access tokens.
API Authentication & Security
Authenticate your developer scripts and AI coding assistants with secure site-scoped bearer tokens.
Generating a Site-Scoped API Token
To authenticate API and MCP requests, generate an access token in your workspace dashboard under Settings → Developer API. Each token is securely scoped to your specific website workspace.
Authorization Header Format
Pass your site token in the standard HTTP Authorization header using the Bearer scheme:
HTTP
Header Format
Authorization: Bearer eo_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxx
Token Security Best Practices
- Never commit API tokens to public Git repositories.
- Store tokens in environment variables (e.g.
EDGEORIGIN_MCP_TOKEN). - Revoke and regenerate tokens immediately if a credential is leaked.
- Tokens inherit workspace permissions and cannot cross tenant boundaries.
