Skip to main content

Module agent

Module agent 

Source
Expand description

What agents use to reach CodoSEO in the cloud: API keys, the REST API’s service layer (shared with the MCP server, so both give the same JSON and charge the same quota) and the Bearer authentication in front of them.

Modules§

anon
The no-key tier of the cloud MCP server: what AnonBackend does over the same store the website’s no-signup audit uses. Nothing here is charged to an API key; abuse is held back by the limits of store::quick: one fresh audit per domain per 24 hours, a daily budget over all agents, the per-IP limits (shared with the website, for clients that connect directly) and the start-monitoring email caps.
auth
Who is calling the API: an API key in Authorization: Bearer <key>, and nothing else. The session cookie never authenticates the API (so no request can ride on a browser login), and a key that is malformed or revoked is refused, never treated as “no key”.
error
What can go wrong in the agent API, with the status, code and message REST answers with ({"error":{"code":"...","message":"..."}}). The MCP server shows message() as a tool error.
keys
Generating and recognising API keys. A key is cdo_ and 43 characters of URL-safe base64 (256 random bits). Only its SHA-256 hash and a 12-character prefix are stored, so the key exists in the clear once, in the response that creates it.
limiter
A small in-memory limiter for the no-key MCP tools: how many calls one client address may make in a sliding window. It guards the database from a client that polls or probes in a tight loop; the audit and email limits that cost something live in the store. One web container is enough for that, so the counts live here and a restart forgets them.
mcp
The cloud MCP server’s backend: CloudBackend over the shared AgentService, so a keyed tool call returns the JSON the REST API returns and is charged to the same daily allowance, and AnonBackend over AnonService for the no-key tools. Errors become the message the agent reads as a tool error (AgentError::message, never raw internal text; quota exhaustion reads the same as over REST).
service
The agent API’s one service layer. The REST routes (/api/v1) and the cloud MCP tools both call these methods, so they return the same JSON (codoseo_mcp::cloud::types) and charge the same daily quota.