MCP
MCP authentication
Bearer MCP key, scope, reveal, dan cabut.
Header
Authorization: Bearer citora_mcp_xxxxxxxxTidak ada query param key. Jangan taruh key di URL.
Kelola key (JWT aplikasi)
Base: /api/brands/{brand_id}/mcp-keys
| Method | Aksi |
|---|---|
GET | Daftar key (prefix, label, scope, last used) |
POST | Buat key — body { "label": "Claude" } — response berisi api_key sekali |
DELETE /{key_id} | Cabut |
| Reveal | Endpoint reveal di UI Settings jika can_reveal true |
Key lama yang dibuat sebelum fitur salin aktif tidak bisa di-reveal. Cabut lalu buat baru.
Scope
| Scope | Efek |
|---|---|
read | Default. Tool tulis tidak didaftarkan / ditolak |
write | Termasuk post, analisis, audit, email laporan, Keyword Magic search |
full | Alias write |
Bridge juga bisa memaksa read-only dengan CITORA_MCP_READ_ONLY=1 (disembunyikan di sisi stdio, server tetap memfilter scope).
Rate limit
60 request / menit / key. Jika terlampaui, agen menerima error rate limit — tunggu jendela 1 menit.
Downgrade paket
Key tidak dihapus. Call tetap 403 sampai MCP aktif lagi di paket brand.