> ## Documentation Index
> Fetch the complete documentation index at: https://sourcebot-sou-1870-scoped-access-tokens.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

To securely access and interact with Sourcebot’s API, authentication is required. Users must generate an API Key, which will be used to authenticate requests.

<Note>
  If [anonymous access](/docs/configuration/auth/access-settings#anonymous-access) is enabled, some endpoints will be accessible without a API key.
</Note>

## Creating an API key

Navigate to **Settings → API Keys** and click **Create API Key**. Copy the value - it is only shown once.

<Frame>
  <img src="https://mintcdn.com/sourcebot-sou-1870-scoped-access-tokens/qOy_CKbI3G2Lq_Q9/images/mcp_api_key_settings.png?fit=max&auto=format&n=qOy_CKbI3G2Lq_Q9&q=85&s=3c662d0ef03ceeb48c38694e0e2d8ccb" alt="API Keys page in Sourcebot Settings" width="2366" height="1122" data-path="images/mcp_api_key_settings.png" />
</Frame>

## Using an API key

Pass your API key as a Bearer token in the `Authorization` header on every request.

```bash theme={null}
Authorization: Bearer <your-api-key>
```

For example, to call the `/api/search` endpoint:

```bash theme={null}
curl -X POST https://your-sourcebot-instance.com/api/search \
  -H "Authorization: Bearer <your-api-key>" \
  -H "Content-Type: application/json" \
  -d '{"query": "hello world", "matches": 10}'
```

## Using a scoped access token

Scoped access tokens are short-lived bearer credentials intended for clients that should only access a specific set of repositories. Create one with a Sourcebot API key by calling `POST /api/ee/scoped_access_token` with repository names:

```bash theme={null}
curl -X POST https://your-sourcebot-instance.com/api/ee/scoped_access_token \
  -H "Authorization: Bearer <your-api-key>" \
  -H "Content-Type: application/json" \
  -d '{"repos": ["github.com/acme/frontend", "github.com/acme/backend"]}'
```

The response contains an opaque token beginning with `sbst_`. It expires exactly one hour after issuance, cannot be refreshed, and is returned only once. Use it as a Bearer token with public API endpoints or the Sourcebot MCP server:

```bash theme={null}
Authorization: Bearer <your-scoped-access-token>
```

Repository scope is bound internally to repository IDs and is also intersected with the creating user's current repository permissions. Creating and revoking scoped access tokens requires an API key; a scoped access token cannot mint or revoke tokens.
