Skip to content
StratifyIQ Docs
Esc
↑↓navigate↵open⌘Jpreview
On this page

Authentication and attribution

Keep caller identity, tenant scope, and the reason for a read attached to each operation.

Caller identity

Use credentials issued through your authorized StratifyIQ connection. Protected API operations use bearer authentication. Keep access tokens out of URLs, screenshots, shared examples, and model prompts.

The broker determines tenant scope from the authenticated principal. Endpoint IDs and request arguments cannot grant a caller access to another tenant.

Endpoint observations

GET /api/mcp/endpoint is an internal loopback-only hop from the native MCP process to the broker. External callers use the native MCP observations tool; they cannot call this HTTP path at api.stratifyiq.com.

The internal HTTP contract requires an agent_id query parameter and the X-StratifyIQ-Reason header. The host prepares this request from the authorized MCP call. The reason must contain 3–500 characters. Optional minutes and limit parameters are bounded by the generated reference.

When ticket attribution is supplied, the host sends X-StratifyIQ-Ticket-Number together with X-StratifyIQ-Ticket-System: connectwise. Runtime ticket policy remains authoritative.

The caller’s host supplies identity and attribution. Model inputs do not grant scope. Authorization, provider, and transport errors remain failures; clients must not convert them into empty successful observations.

See the API reference for the exact current wire shapes.

Was this page helpful?