Authentication
Every request, REST or MCP, is authenticated with the same bearer API key. Keys act as your account: strategies created through the API belong to you and are the ones you see in the app.
curl "https://api.rivo.markets/v1/universe" \
-H "Authorization: Bearer rivo_live_..."Creating a key
Keys are created in Settings, under Developer, and start with rivo_live_. The full key is shown exactly once at creation; we store only a hash, so a lost key cannot be recovered, only replaced. You can hold up to 10 active keys, which is enough for one per client or environment.
Scopes
Every key carries scopes, and a new key gets read only. Ask for more when you create it, and give a key the least it needs: a key that only reads cannot be made to spend money by a bug or a confused agent.
read: every GET, every backtest. Changes nothing.write: account state. Follows, exit rules, saved strategies, marking alerts read, and paper autopilot. Also pausing or turning off autopilot, which deliberately needs less than turning it on.trade: money. Placing and selling orders, and enabling autopilot with real money.
Scopes are enforced on the MCP server by not registering the tool at all. A read-only key is never offered a tool it cannot use, so a model cannot get stuck retrying a write it will never be allowed to make.
A key holding trade also sees contract identifiers on positions and quotes, because selling and redeeming are impossible without them. Keys without it never do.
Spend caps
A key can carry a daily spend cap in USD, set when you create it. It is checked before every order and is separate from the per-follow daily cap in an autopilot config: this one bounds this credential, which is what you want when handing a key to something you did not write. A rejected order releases its reservation, so a failure does not eat the day.
Revoking a key
Revoke from the same Settings page. Revocation is immediate and permanent: revoked keys stay listed for your records but never authenticate again. There is no way to un-revoke, so treat a leaked key as gone and mint a new one.
Key management stays in the app
Keys cannot create, list or revoke other keys, and cannot grant themselves a scope. Management requires a signed-in browser session, so a leaked key is contained: it can do what its scopes allow, but it cannot widen them, mint itself a replacement, or lock you out.
Auth errors
401: the key is missing, malformed or revoked. Send it asAuthorization: Bearer rivo_live_....403with codeSCOPE_REQUIRED: the key is valid but lacks the scope the endpoint needs, or the account behind it has no active subscription. Neither is fixed by re-creating the key: grant the scope on a new key, or fix the subscription and the existing key starts working again.
The full error catalogue is on the Errors page.