Machine API Keys
Create and revoke persona-scoped machine API keys for HTTP and MCP. Keys follow the same app-feature gates as a signed-in session.
Machine API keys let a bootstrap admin issue a secret bound to one staff persona. Callers send the key on HTTP (x-api-key or Authorization: Bearer ol_…) or on a persona MCP server. The key receives the same personas a JWT session with that role would get, and the same app-feature gates. Other OpenLegacy products can use that key to create a CRM signal when someone signs up or starts a marketplace subscription, including name, company, role, and where they signed up.