Authentication

The Platica API uses Bearer authentication. The Authorization header accepts two credentials:

CredentialPrefixWhat it's for
API Keypl_key_REST integrations, scripts, CI, Postman. Full access to the key's workspace.
OAuth (MCP)pl_at_Access token Platica issues when you connect an MCP client. It carries your user, the workspaces you authorized, your scopes, and your role.
Authorization: Bearer pl_key_xxxxxxxxxxxxx
Authorization: Bearer pl_at_xxxxxxxxxxxxx

To connect Cursor, Claude, or VS Code, don't generate a key: paste https://api.platica.mx/mcp and authorize. The full guide is in MCP Authentication . The rest of this page covers the API Key, which is still the path for curl and the REST API.


Header format

Authorization: Bearer pl_key_xxxxxxxxxxxxx

An MCP OAuth token uses the same header with the pl_at_ prefix.


Get your API Key

You can generate your API Key directly from the Platica dashboard, with no need to contact the support team.

  1. Open settings — From the Platica dashboard, go to Settings and select the API Keys section.

  2. Create a new API Key — Click Create new API Key and enter a descriptive name to identify it.

  3. Save your API Key — The API Key is shown only once. Copy it and store it somewhere safe; you won't be able to see it again.

  4. Configure your requests — Include the API Key in the header of every request you make to the API.


Example authenticated request

curl -X GET "https://api.platica.mx/v1/agents" \
  -H "Authorization: Bearer pl_key_xxxxxxxxxxxxx" \
  -H "Content-Type: application/json"

Important considerations

Your API Key has access only to the workspace it was created in. This means:

  • You can only manage agents, customers, and conversations within that workspace.
  • It will not have access to other workspaces, even if your account belongs to them.
  • If you need to access several workspaces via the API, you must generate an API Key in each one.

Authentication errors

If your API Key is invalid or missing, you'll receive a 401 Unauthorized error:

{
  "code": 401,
  "error": "Unauthorized",
  "details": "Invalid or missing API key"
}

With an OAuth token (pl_at_…) the 401 includes a WWW-Authenticate header pointing at discovery (RFC 9728). A 403 for a missing platica:write uses the insufficient_scope challenge so the client can step up. Details in MCP Authentication and Errors .

If the credential covers several workspaces, writes require ?workspace=<id>. GET /v1/workspaces lists the IDs that credential can use.