Authentication & scopes

How to authenticate REST and MCP requests to WEXTL, the scope model, and least-privilege guidance for Personal Access Tokens.

AI-assisted documentation

This documentation is compiled from our own product source code and internal specs, the platform's public API specification, and anonymized requests logs we collect from our support team[2].

You need an active WEXTL account with at least one organization. Mint a Personal Access Token from Dashboard → API, or complete an OAuth sign-in instead if your client supports it.[1]

text
Authorization: Bearer wextl_...
  1. Mint a new Personal Access Token.
  2. Update your integration to use the new token.
  3. Confirm calls succeed with the new token.
  4. Revoke the old token.
  1. WEXTL® authentication and scope-check implementation.
  2. Our users' real API keys and OAuth grants in use.
  3. OAuth 2.1 specification.