Authentication
Interactive MCP clients should use OAuth 2.1 with PKCE and workspace-bound access tokens. MCP clients with custom-header support and REST automation may instead send a workspace API key in x-api-key.
REST retries may send Idempotency-Key. The CLI generates one automatically and MCP derives one from the credential and JSON-RPC request ID.