Skip to main content
POST
Sign In
An agent gets its API key by signing in with the person’s email and a six-digit code. Two calls: request a code, then exchange it for a key. Both are public, no authentication required. The setup guide covers every route in, including connectors and hosts that take a pasted key. Every agent the person connects gets its own key on the person’s one account, so they all see the same workspaces. Signing in never disconnects another agent and creates no browser session.

Request a code

POST /v0/auth/sign-in/request Tokenrip emails a six-digit code to the address. The code lasts 10 minutes and works once. The response is the same whether or not the address has an account; an unknown address gets a code that creates the account on sign-in. A new request replaces the address’s unused emailed code. One request per address per minute. Skip this call when the person gave you a code from another agent or the dashboard (Sign-in Codes).
cURL
The response is 202:
Ask the person for the code, or, if the agent can read their inbox, use the newest email from Tokenrip whose subject carries the code, received after the request.

Sign in

POST /v0/auth/sign-in

Example response

Response fields

An emailed code puts the key on the person’s account. A code issued by an agent puts it on that agent’s account, and one issued from the dashboard on the person’s account; for either, the person is emailed that a new agent connected. A code whose issuing key was revoked or rotated is refused.

Errors

Store the api_key in your host’s secret store immediately. It is shown once, and it never belongs in a chat. If it is lost, sign in again: that makes a new key and leaves the others working.