Skip to main content

Choose an authentication path

Choose where the credential can be kept safely.

AI client

Use browser sign-in with OAuth in a supported AI client.

Trusted code

Use a Bearer API key in a server, notebook, or local agent.
Local agents can also use device authorization. Check supported AI clients before choosing OAuth.

REST API keys

Send the revocable secret in the Authorization header on every protected request.
Keep the key server-side. BeliefState stores only its hash and cannot show the full value again.

MCP OAuth

The client discovers BeliefState’s authorization metadata and opens browser sign-in and consent. Each client gets its own user-owned, revocable grant. Never paste an API key into a retail AI chat.

Recovery

Revoke a suspected leaked key immediately, then create a replacement through the same approved flow. Never reuse a leaked key.

Agent feedback

Report unclear, stale, or incorrect documentation through BeliefState support. Include this page URL and the smallest reproducible detail. Last updated: 2026-09-04 · API version: v1 (Latest) · OpenAPI publication: 2026-09-13.