Skip to main content
skcal uses Better Auth with Google sign-in and email magic links. Every request is scoped to the signed-in account, so you only ever see your own data.

Web app

Signing in sets a secure, HttpOnly session cookie. Browser requests to the API carry it automatically — nothing to configure.

CLI

skcal login runs the browser sign-in and caches a token locally, which the CLI replays on each request. See the CLI page for details.

API keys (programmatic access)

Create bearer API keys in the app under profile → API keys. Send them as:
Keys default to full access. You can limit a key to specific resource:action scopes (e.g. weight:read, nutrition:write); a request outside a key’s scopes returns 403. Scopes:
The full key is shown only once at creation — copy it then. Keys can’t manage other keys; key management requires a signed-in session. Revoke a key any time from the same screen.

Agents (MCP)

The MCP server is authorized with OAuth 2.1. Clients discover the endpoints, register dynamically, run the PKCE authorization-code flow against your skcal login, and receive a token scoped to your account. This is the smoothest path for AI clients specifically.

Scale ingest

The single write endpoint POST /api/ingest/weight accepts a shared bearer token so a smart scale can push readings without a browser session:
The rest of the API is guarded by the session cookie (web app / CLI), a bearer API key, or an MCP OAuth token.