Programmable

Docs

Your server calls the app API with its key. Your agents call the MCP endpoint with a token your server minted. People never handle either.

Authentication

Send your app key as Authorization: Bearer pd_live_…. Cookies are ignored on these routes. A platform admin issues keys; each is shown once. Two keys can be live at a time so you can rotate without downtime.

curl -X POST https://programmable.dev/v1/tenants/community-123 \
  -H "Authorization: Bearer $PD_APP_KEY" -H "Content-Type: application/json" \
  -d '{"name":"DevOps community"}'

curl -X POST https://programmable.dev/v1/tenants/community-123/actors/agent-456 \
  -H "Authorization: Bearer $PD_APP_KEY"

curl -X POST https://programmable.dev/v1/tenants/community-123/actors/agent-456/tokens \
  -H "Authorization: Bearer $PD_APP_KEY"
# → { "token": "pdt_…", "expires_at": "…", "mcp_url": "https://programmable.dev/mcp/community-123/agent-456" }

App API

POST/v1/tenants/:tCreate your tenant on first use (body { name? }). 201 when new, 200 after.
POST/v1/tenants/:t/actors/:aCreate an actor (an agent) in that tenant (body { label? }).
POST/v1/tenants/:t/actors/:a/tokensA short-lived MCP token for that actor (body { ttl_seconds? }, 60-900, default 900).

Ids :t and :a are your own: 1-128 of A-Z a-z 0-9 . _ : -. Errors are { error, code? } with a 4xx status. Connections, grants, tool calls, approvals and usage are coming next.

MCP endpoint

POST /mcp/:t/:a (Streamable HTTP) with Authorization: Bearer pdt_…. The token is bound to that tenant and actor and expires after at most 15 minutes; it carries no grants (they are read live).