Skip to main content
ECN has two authenticated surfaces, each with its own credential type.

REST API tokens

Authenticate as a user and receive a token:
Send the token on every request:
A token is scoped to your user. Workspace data is additionally scoped to the Organization you are a member of. Some endpoints (e.g. /credits/wallet/, /mcp/keys/) take an explicit organization_id — find yours in the organizations array returned by GET /auth/me/:

MCP API keys

Chat clients (claude.ai, Claude Desktop, ChatGPT, Grok) and Claude Code sign in to the MCP server with OAuth — no key needed; see Connect Claude, ChatGPT and Grok. Clients that cannot sign in (Cursor, scripts) use an API key prefixed ecn_mcp_. A key belongs to the member who created it, acts as them, and reaches every enterprise they belong to; it is shown only once at creation.
1

From the portal

Settings → Developers → Create key (open it). Copy the secret immediately.
2

Or via the API

The MCP server (https://www.earthcare.network/mcp) accepts the key as Authorization: Bearer ecn_mcp_…, X-MCP-API-Key, or X-Api-Key. Revoke a key in Settings → Developers, or with DELETE /api/v1/mcp/keys/<key_id>/?organization_id=<org_uuid> (the organization_id is required).
An ecn_mcp_… key acts as you. Keep it out of version control and shared configs; prefer OAuth wherever the client supports it.