Expand description
What agents use to reach CodoSEO in the cloud: API keys, the REST API’s service layer (shared with the MCP server, so both give the same JSON and charge the same quota) and the Bearer authentication in front of them.
Modules§
- anon
- The no-key tier of the cloud MCP server: what
AnonBackenddoes over the same store the website’s no-signup audit uses. Nothing here is charged to an API key; abuse is held back by the limits ofstore::quick: one fresh audit per domain per 24 hours, a daily budget over all agents, the per-IP limits (shared with the website, for clients that connect directly) and the start-monitoring email caps. - auth
- Who is calling the API: an API key in
Authorization: Bearer <key>, and nothing else. The session cookie never authenticates the API (so no request can ride on a browser login), and a key that is malformed or revoked is refused, never treated as “no key”. - error
- What can go wrong in the agent API, with the status, code and message REST answers with
(
{"error":{"code":"...","message":"..."}}). The MCP server showsmessage()as a tool error. - keys
- Generating and recognising API keys. A key is
cdo_and 43 characters of URL-safe base64 (256 random bits). Only its SHA-256 hash and a 12-character prefix are stored, so the key exists in the clear once, in the response that creates it. - limiter
- A small in-memory limiter for the no-key MCP tools: how many calls one client address may make in a sliding window. It guards the database from a client that polls or probes in a tight loop; the audit and email limits that cost something live in the store. One web container is enough for that, so the counts live here and a restart forgets them.
- mcp
- The cloud MCP server’s backend:
CloudBackendover the sharedAgentService, so a keyed tool call returns the JSON the REST API returns and is charged to the same daily allowance, andAnonBackendoverAnonServicefor the no-key tools. Errors become the message the agent reads as a tool error (AgentError::message, never raw internal text; quota exhaustion reads the same as over REST). - service
- The agent API’s one service layer. The REST routes (
/api/v1) and the cloud MCP tools both call these methods, so they return the same JSON (codoseo_mcp::cloud::types) and charge the same daily quota.