Developer documentation
Use scoped organization tokens or a registered OAuth client to read and update company details. Every operation validates organization access.
Create a token in Organization → API tokens. Send it in an Authorization: Bearer header. Keep tokens on your server and never include them in browser code.
First request /api/v1/credential-context to discover the organization ID bound to your credential. Use that ID as ORG_ID in company requests.
curl "$STRATA_URL/api/v1/credential-context" \
-H "Authorization: Bearer $STRATA_TOKEN"
curl "$STRATA_URL/api/v1/organizations/$ORG_ID" \
-H "Authorization: Bearer $STRATA_TOKEN"Connect a registered MCP client to /mcp using Streamable HTTP and OAuth authorization with PKCE. Discovery is available at /.well-known/oauth-protected-resource/mcp. Ask your operator to register a new client.
Call context_get first to discover the organization ID and effective scopes, then supply that ID to company tools.
Company reads require organizations:read. Writes require organizations:write and the current resource version.
Supply the organization ID on every organization operation. Switching your active organization never retargets a token.
Read company details first, then include its version when updating. Omitted company fields keep their existing values; send an empty string to clear a field. A conflict means you need to refresh before retrying.
401 asks for authentication; 403/404 denies access; 409 indicates a conflict; 429 asks you to wait. Request IDs help trace failures.