MCP
Authentication
How the server knows who is calling, which workspace they are in, and what they may do.
The key is the identity
Every request carries Authorization: Bearer wf_live_…. The workspace comes from the key: no tool takes a workspace or account argument, so a key can only ever act inside its own workspace.
Scopes are checked before anything runs
tools/list returns only the tools the key’s scopes allow, and tools/call checks the scope again before the tool runs. A refused call returns a readable error naming the missing scope.
Errors and limits
| Situation | What happens |
|---|---|
| No key, or an invalid or revoked key | HTTP 401 |
| The key lacks a tool's scope | The tool returns an error naming the scope it needs |
| More than 120 requests a minute from one address | HTTP 429 — slow down and retry |
| A batch of more than 20 calls | Refused as an invalid request |
| A GET request | HTTP 405 — the server takes POST only |