Authentication
Who identifies how: nobody for the public routes, an account for everything else.
| Who | How | For |
|---|---|---|
| Anyone | no sign-in | the public routes |
| An app acting for you | OAuth 2.1 | the two MCP servers |
| Your own agent or service | Authorization: Bearer ath_... | Athaus für Makler and the app's routes |
| Athaus's own apps | session cookie | the signed-in surfaces, not for third parties |
With a key
curl https://api.athaus.ai/api/public/properties \
-H "Authorization: Bearer ath_..."A key only counts when the request carries no session cookie. It belongs to one person and sees what that person sees in the app.
Every key may read (GET, HEAD, OPTIONS). Writing (POST, PUT, PATCH, DELETE) outside the MCP servers is only allowed for a key with the right freigeben (approve); any other key gets 403:
{ "error": "schluessel_recht_fehlt" }On the MCP servers the rights apply per tool (Rights).
What a key cannot do
- Consent to a connection or disconnect one: that needs sign-in in the browser.
- Subscribe to MCP Events: only an OAuth connection can.