# Authentication and access

## Scoped machine keys

Send `Authorization: Bearer <YOUR_API_KEY>` over HTTPS. A machine key is bound to its tenant; do not attach human workspace selectors to machine requests. Keep keys in server-side secret storage or an MCP client's private credential settings. Never place keys in query strings, prompts, shared configuration or logs.

Keys are subject to current scopes, workspace policy, hierarchy, expiry and revocation. Delegated key lifetimes cannot exceed their issuer's lifetime. Revoking a key disables its delegated descendants. Rotation overlap defaults to zero.

REST key issue/rotation returns the new secret once. An idempotent replay may show completion with `secretAvailable: false`; inspect metadata and rotate if a usable secret is still needed. MCP never returns the raw key secret: when configured, authorized key-management tools return a short-lived human claim link.

## Human administration

Initial API enablement and access-control changes require a verified human administrator. Human sessions can select a permitted workspace using `X-Engage-Meta-Organization` and `X-Engage-Organization`; the server verifies the selection against persisted authority. Machine and OAuth principals cannot use these selectors to switch tenants.

## OAuth

OAuth and dynamic client registration are currently off in this release. Tenant API enablement alone does not enable OAuth. Clients that require OAuth cannot yet use this rollout through that flow. Check [release status](/engage/release-status) before configuring an assistant.