bymundi API

Authentication

Personal API keys — how to create, send, rotate and revoke them.

Keys

Every request carries a personal API key:

Authorization: Bearer bym_live_...

Staff create keys in bymundi under Integrations → API & MCP. A key:

bym_live_ keys work against production. bym_test_ keys come from test deployments and are refused by production.

The API is in early access: your agency needs API access switched on by bymundi.

Keep keys secret

Treat a key like a password. Keep it in a secret store or an environment variable, never in a browser, a mobile app or a repository. The MCP endpoint refuses browser origins (origin_not_allowed) for the same reason.

Rotating

Create the new key, deploy it, then revoke the old one. Both work in between.

Who did what

Every write is recorded with the key that made it. Staff see it under Activity in the same screen, filterable by key.