Authentication
Personal API keys — how to create, send, rotate and revoke them.
Keys
Every request carries a personal API key:
Authorization: Bearer bym_live_...
Staff create keys in bymundi under Integrations → API & MCP. A key:
- acts as the person who created it. It sees what they see and does what they may do in the app, capped at an agent's powers: a key never has admin powers, even when its owner is an admin.
- carries permissions chosen when it is created.
- is shown once. bymundi stores only a hash; if you lose it, create another.
- expires after 30, 90 or 365 days, or never, as chosen at creation.
- can be revoked at any moment from the same screen; the next request with it answers
401 unauthorized.
bym_live_ keys work against production. bym_test_ keys come from test deployments and are refused by production.
The API is in early access: your agency needs API access switched on by bymundi.
Keep keys secret
Treat a key like a password. Keep it in a secret store or an environment variable, never in a browser, a mobile app or a repository. The MCP endpoint refuses browser origins (origin_not_allowed) for the same reason.
Rotating
Create the new key, deploy it, then revoke the old one. Both work in between.
Who did what
Every write is recorded with the key that made it. Staff see it under Activity in the same screen, filterable by key.