AthausDocs

Authentication

Who identifies how: nobody for the public routes, an account for everything else.

WhoHowFor
Anyoneno sign-inthe public routes
An app acting for youOAuth 2.1the two MCP servers
Your own agent or serviceAuthorization: Bearer ath_...Athaus für Makler and the app's routes
Athaus's own appssession cookiethe signed-in surfaces, not for third parties

With a key

curl https://api.athaus.ai/api/public/properties \
  -H "Authorization: Bearer ath_..."

A key only counts when the request carries no session cookie. It belongs to one person and sees what that person sees in the app.

Every key may read (GET, HEAD, OPTIONS). Writing (POST, PUT, PATCH, DELETE) outside the MCP servers is only allowed for a key with the right freigeben (approve); any other key gets 403:

{ "error": "schluessel_recht_fehlt" }

On the MCP servers the rights apply per tool (Rights).

What a key cannot do

  • Consent to a connection or disconnect one: that needs sign-in in the browser.
  • Subscribe to MCP Events: only an OAuth connection can.

On this page