Authentication
Burrowbox uses bearer tokens in the Authorization header.
Authorization: Bearer <token>
| Token | Prefix | Scope | Where to get it |
|---|---|---|---|
| API key | tmk_ |
Everything your account can do: machines, billing, platform MCP | Dashboard → Account → API keys |
| Machine token | tmm_ |
Only that machine's MCP endpoint and live-view links | mcpToken in the machine response |
| Session cookie | — | The dashboard in your browser | Signing in |
#API keys
API keys act as your user. Keep them on your server. Create one key per integration so you can revoke them independently; the dashboard shows when each key was last used.
#Machine tokens
A machine token only works on two endpoints, and only for its own machine: POST /api/machines/{id}/mcp and POST /api/machines/{id}/live-view (so an agent can share its screen; see Embed the live view). It can't list, create, stop or bill anything. This is the token to hand to an agent, including agents acting for your customers.
#Accounts
These endpoints power the dashboard. Browser requests must come from the Burrowbox origin.
| Method | Path | Body | |
|---|---|---|---|
POST |
/api/auth/register |
email, password, name |
Creates the account and signs in. A confirmation email is sent. |
POST |
/api/auth/login |
email, password |
Signs in (sets the session cookie) |
POST |
/api/auth/logout |
— | Signs out this session |
POST |
/api/auth/verify |
token |
Confirms the email address from the link in the email. The welcome credit is added once the email is confirmed and a card is saved. |
POST |
/api/me/verify-email |
— | Sends a new confirmation email (signed in) |
POST |
/api/auth/forgot |
email |
Emails a password-reset link. Always returns {"ok": true}, so it can't be used to find out which emails have accounts. |
POST |
/api/auth/reset |
token, password |
Sets a new password from the reset link, signs out every other session, and signs you in |
Links in emails are single-use: confirmation links last 24 hours and reset links last 1 hour. Only a hash of each link is stored. Changing or resetting a password also sends a security notice to the account's address.
#Rate limits
Sign-in and sign-up are rate-limited per IP address and per email. API calls are not metered by count, only by machine time.
#Security notes
- Requests authenticated by the session cookie must come from the Burrowbox origin; cross-site requests are rejected.
- Tokens are stored hashed. If you lose an API key, revoke it and create a new one.