> ## Documentation Index
> Fetch the complete documentation index at: https://docs.robase.dev/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For chatbots and coding agents, start at /guides/ai-agents.
> Hosted MCP: POST https://api.robase.dev/mcp (Streamable HTTP). Auth: Authorization: Bearer robe_… or robe_agent_….
> Phase 1 tools: get_pricing, send_otp, verify_otp, get_otp, send_sms, get_sms. No payment or top-up tools.
> Call get_pricing; treat listed:true as marketed markets (NG, GH, KE, ZA, GB, BJ, CI, US). Do not invent countries or delivery percentages.
> Prefer OTP-shaped tests such as "Your Robase test OTP is 123456". Do not send Hello or Good morning as tests. Match errors on error.type.

# Authentication

> API keys are Bearer tokens. Live keys start with robe_ plus 64 hex characters.

Every `/v1` request needs an API key from the [dashboard](https://robase.dev/app/api-keys):

```
Authorization: Bearer robe_your_api_key_here
```

## Key format

Keys are generated in `internal/core/auth/auth.go`: the prefix `robe_` plus 32 random bytes encoded as 64 hex characters. Agent keys created for MCP use `robe_agent_` plus the same 64 hex characters — they still start with `robe_`, so existing auth accepts them. The full secret is shown once at creation and stored as a SHA-256 hash. Revoke unused keys from the dashboard.

Hosted MCP (`https://api.robase.dev/mcp`) uses the same Bearer header. Prefer a dedicated Agent key and revoke it if it leaks. See [AI agents](/guides/ai-agents).

There is no separate test-mode prefix. Dashboard **test send** buttons spend real credits and deliver to real numbers.

## Scopes

A key belongs to one workspace. Dashboard routes use session cookies, not these keys.

Each key also has scopes, which decide which `/v1` endpoints and MCP tools it may call:

| Scope | Allows |
| - | - |
| `otp:send` | `POST /v1/otp/send`, MCP `send_otp` |
| `otp:verify` | `POST /v1/otp/verify`, MCP `verify_otp` |
| `sms:send` | `POST /v1/sms/send`, MCP `send_sms` |
| `read` | `GET /v1/otp/{id}`, `GET /v1/sms/{id}`, MCP `get_otp`, `get_sms`, `get_pricing` |
| `approvals:request` | Reserved for approval requests. No endpoint uses it yet. |

* An **Agent** key must be given at least one scope when you create it.
* A standard key created without scopes has full access.
* Keys created before scopes existed keep full access. The dashboard marks such Agent keys **Legacy full access**. To narrow one, create a new Agent key with the scopes it needs and revoke the old one.

A call without the scope it needs returns `403` with `error.type: insufficient_scope` and `error.required_scope`. Over MCP, `tools/list` shows only the tools the key may call.

## Official SDKs

Pass the key into the client. The SDKs attach `Authorization` and generate an `Idempotency-Key` on every POST:

```ts theme={null}
import { Robase } from "@robasedev/sdk";
const robase = new Robase({ apiKey: process.env.ROBASE_API_KEY });
```

```go theme={null}
import robase "github.com/mantissatech/robase-sdk-go"
client, err := robase.New(os.Getenv("ROBASE_API_KEY"))
```

```php theme={null}
$robase = new Robase\Client(getenv('ROBASE_API_KEY'));
```

## Base URL

| Environment | URL |
| - | - |
| Production | `https://api.robase.dev` |
| Local | `http://localhost:8080` |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.