MunchReach API authentication

How bearer tokens work, what scopes do, and how to debug a 401 or 403.

Updated Sep 10, 2026 1 min read

Every API request carries a bearer token:

Authorization: Bearer mr_live_…

Short answer

No header, no access. The key identifies both the caller and the workspace, so there is no separate workspace ID to pass.

Scopes

A key is created with an explicit set of scopes and can only do what those scopes allow:

  • campaigns:read, campaigns:write
  • contacts:read, contacts:write
  • sequences:read, sequences:write
  • mailboxes:read
  • analytics:read
  • replies:read
  • webhooks:read, webhooks:write

Two blanket scopes also exist: read (read access to everything the API exposes) and write (read and write access to everything).

Checking what a key can do

GET /me returns the key's workspace, its scopes and its per-minute rate limit. Call it first whenever an integration misbehaves.

Error responses

  • 401 unauthorized / invalid_api_key — missing or malformed key
  • 401 api_key_revoked — the key was revoked in Settings → API Keys
  • 401 api_key_expired — the key passed its expiry date
  • 403 insufficient_scope — the key is valid but lacks the scope for that endpoint

Important notes

Treat a key like a password. Store it in an environment variable or a secret manager, never in front-end code or a public repository.

Was this article helpful?

Frequently asked questions

Can one key access several workspaces?
No. A key resolves to exactly one workspace. Create a separate key per workspace.
Can I widen a key's scopes later?
Create a new key with the scopes you need and revoke the old one. Scopes are fixed at creation so an existing integration's blast radius cannot silently grow.

Related articles