Skip to content

API and MCP access

Understand the current headless door and the organization policy that can close or restrict it.

API and MCP provide headless access to Tindre’s governed capabilities. The door acts as an authenticated person or as an organization key — never as an anonymous visitor.

REST API

Direct HTTP resources and operations.

  • Personal access token
  • Typed resource endpoints
  • Live permission checks
  • No OAuth access token

MCP

Capability discovery for AI clients.

  • OAuth or personal token
  • Search and call tools
  • Optional semantic query
  • Proposal flow for controlled writes

Organization policy applies first

Under Administration → Security, administrators can disable API and MCP or force the door to read-only. These settings are ceilings, not grants.

Browser sessions remain available

Turning off API and MCP does not disable the signed-in dashboard. This prevents an administrator from locking themselves out of the page used to restore headless access.

There is a read-only door too

The same address with /read appended exposes a narrower server: the same catalog and the same permissions, minus everything that changes anything. It exists for hosts that are only allowed to call read-only tools. The credential is unchanged — the same token still writes on the ordinary endpoint.

Use the right credential

Personal access tokens work on REST and MCP. OAuth access tokens work only on MCP. Organization keys reach only the separate open-Standard read lane.

Expect typed refusals

Authentication, permissions, rate limits, and disabled policy produce different responses. Handle the actual error rather than retrying every refusal as a transient network problem.