Authentication
The Platica API uses Bearer authentication. The Authorization header accepts two credentials:
| Credential | Prefix | What it's for |
|---|---|---|
| API Key | pl_key_ | REST integrations, scripts, CI, Postman. Full access to the key's workspace. |
| OAuth (MCP) | pl_at_ | Access token Platica issues when you connect an MCP client. It carries your user, the workspaces you authorized, your scopes, and your role. |
Authorization: Bearer pl_key_xxxxxxxxxxxxx
Authorization: Bearer pl_at_xxxxxxxxxxxxx To connect Cursor, Claude, or VS Code, don't generate a key: paste https://api.platica.mx/mcp and authorize. The full guide is in MCP Authentication . The rest of this page covers the API Key, which is still the path for curl and the REST API.
Header format
Authorization: Bearer pl_key_xxxxxxxxxxxxx An MCP OAuth token uses the same header with the pl_at_ prefix.
Get your API Key
You can generate your API Key directly from the Platica dashboard, with no need to contact the support team.
Open settings — From the Platica dashboard, go to Settings and select the API Keys section.
Create a new API Key — Click Create new API Key and enter a descriptive name to identify it.
Save your API Key — The API Key is shown only once. Copy it and store it somewhere safe; you won't be able to see it again.
Configure your requests — Include the API Key in the header of every request you make to the API.
Example authenticated request
curl -X GET "https://api.platica.mx/v1/agents" \
-H "Authorization: Bearer pl_key_xxxxxxxxxxxxx" \
-H "Content-Type: application/json" Important considerations
Keep your API Key safe. Do not expose it in public code, repositories, or client-side applications. If you suspect it has been compromised, immediately contact integraciones@platica.mx .
Your API Key has access only to the workspace it was created in. This means:
- You can only manage agents, customers, and conversations within that workspace.
- It will not have access to other workspaces, even if your account belongs to them.
- If you need to access several workspaces via the API, you must generate an API Key in each one.
Authentication errors
If your API Key is invalid or missing, you'll receive a 401 Unauthorized error:
{
"code": 401,
"error": "Unauthorized",
"details": "Invalid or missing API key"
} With an OAuth token (pl_at_…) the 401 includes a WWW-Authenticate header pointing at discovery (RFC 9728). A 403 for a missing platica:write uses the insufficient_scope challenge so the client can step up. Details in MCP Authentication and Errors .
If the credential covers several workspaces, writes require ?workspace=<id>. GET /v1/workspaces lists the IDs that credential can use.