Web app
Signing in sets a secure, HttpOnly session cookie. Browser requests to the API carry it automatically — nothing to configure.CLI
skcal login runs the browser sign-in and caches a token locally, which the
CLI replays on each request. See the CLI page for details.
API keys (programmatic access)
Create bearer API keys in the app under profile → API keys. Send them as:resource:action scopes (e.g. weight:read, nutrition:write); a request
outside a key’s scopes returns 403. Scopes:
The full key is shown only once at creation — copy it then. Keys can’t manage
other keys; key management requires a signed-in session. Revoke a key any time
from the same screen.
Agents (MCP)
The MCP server is authorized with OAuth 2.1. Clients discover the endpoints, register dynamically, run the PKCE authorization-code flow against your skcal login, and receive a token scoped to your account. This is the smoothest path for AI clients specifically.Scale ingest
The single write endpointPOST /api/ingest/weight accepts a shared bearer
token so a smart scale can push readings without a browser session:
The rest of the API is guarded by the session cookie (web app / CLI), a bearer
API key, or an MCP OAuth token.