> ## Documentation Index
> Fetch the complete documentation index at: https://docs.straddle.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication and permissions

> Understand API key access, client approvals, and the Straddle skills request rules.

API MCP sends requests with your Straddle API key. The key's permissions determine which Straddle operations the server can execute; your client controls when it asks you to approve a tool request.

## Supply the API key

Set `STRADDLE_API_KEY` in the environment that starts your client, or use the Straddle plugin's credential field in Cursor. Direct client configuration stores a reference to the variable. See [Connect MCP](/developer-tools/mcp/install) for the exact syntax.

Use a key from the [Straddle dashboard](https://dashboard.straddle.com). API MCP uses that key as a bearer token and needs no Scalar login. Keep the key in the client environment or credential field, outside prompts, source files, and reports.

A key saved in the Straddle CLI configures the CLI. Configure the MCP client's credential separately.

## Match the environment

Choose the host explicitly in each API request:

| Environment | `serverBaseUrl` |
| - | - |
| Sandbox | `https://sandbox.straddle.com` |
| Production | `https://production.straddle.com` |

Use a key for the same environment. Confirm the key's environment in the dashboard and the host in the request.

## Review API execution

The API MCP's `execute-request` can perform reads, creates, updates, deletes, and sensitive-data operations permitted by the key. A production key can authorize production writes.

Keep tool approval prompts enabled. Before approving execution, inspect the method, host, path, account header, and request body. For a write, check the intended effect and the idempotency key as well.

## Understand the skill rules

The Straddle skills add instructions for integration work. These are workflow rules followed by the agent, separate from the server's API permissions:

| Skill rule | What you review |
| - | - |
| Use sandbox for integration writes. | The explicit sandbox host and matching key. |
| Preview a write before asking for approval. | Account, operation, payload summary, external ID, and idempotency key. |
| Ask again when the target or payload changes. | The revised request. |
| Route customer, paykey, charge, and payout creation through the SDK or CLI. | The generated code or CLI preview. |
| Route deletes, unmasking, and paykey reveal through the SDK or CLI. | The specific approved action and handling of sensitive output. |

The agent follows these routing instructions. The server still accepts any operation permitted by the supplied key.

## Interpret verification

Documentation search and specification discovery can succeed without an authenticated Straddle request. Verify API access with a permitted read against the environment and account you intended.

A successful read proves access to that operation and account. Follow [Read an account through API MCP](/developer-tools/mcp/api-requests) for a focused check.


## Related topics

- [Read an account through API MCP](/developer-tools/mcp/api-requests.md)
- [Connect your agent to Straddle](/developer-tools/mcp/overview.md)
- [Choose your tools](/developer-tools/routing.md)
- [Ruby SDK for Straddle](/api-reference/sdk/ruby.md)
- [Node.js SDK for Straddle](/api-reference/sdk/node.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.